CVE-2024-0284

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Jan 7, 2024
Updated: May 17, 2024
CWE ID 79

Summary

CVE-2024-0284 is a newly disclosed vulnerability affecting the Kashipara Food Management System up to version 1.0. This issue has been classified as problematic, allowing for cross-site scripting (XSS) attacks. The vulnerability is tied to the processing of the file party_submit.php, which can be exploited by manipulating the argument party_address. Attackers can initiate these attacks remotely, making this a significant security concern. The exploit for this vulnerability (VDB-249839) has already been made public, increasing the risk to affected systems.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share