CVE-2022-36244
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2022-36244: Shop Beat Media Player, versions 2.5.95 to 3.2.57, features multiple Stored Cross-Site Scripting (XSS) vulnerabilities. These weaknesses, discovered in the Shop Beat Control Panel available at controlpanel.shopbeat.co.za, can be exploited by attackers to inject harmful scripts into web pages viewed by other users. The XSS vulnerabilities pose a significant risk, as they can lead to account takeover, data theft, and other malicious activities. Organizations utilizing this media player are advised to install patches or updates as soon as possible to mitigate these risks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.