CyberRota Analysis
AI-GeneratedFunnelKit Funnel Builder versions up to and including 3.15.0.8 are susceptible to a reflected cross-site scripting (XSS) vulnerability due to improper input neutralization during web page generation. This flaw could allow attackers to execute arbitrary scripts in the context of a user's session, potentially leading to data theft or session hijacking. Organizations using affected versions of Funnel Builder should prioritize patching this vulnerability to mitigate the associated security risks.
Original NVD Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FunnelKit Funnel Builder by FunnelKit funnel-builder allows Reflected XSS.This issue affects Funnel Builder by FunnelKit: from n/a through <= 3.15.0.8.