CVE-2024-11175

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Nov 13, 2024
Updated: Nov 15, 2024
CWE ID 94
CWE ID 79

Summary

CVE-2024-11175 is a newly disclosed vulnerability affecting Public CMS 5.202406.d. This issue lies in the processing of the file /admin/cmsVote/save within the Voting Management component. An attacker can exploit this cross-site scripting (XSS) vulnerability remotely, making it a significant concern. The exploit has become publicly available, increasing the risk for potential attacks. To mitigate this threat, it is strongly advised to apply the patch labeled b9530b9cc1f5cfdad4b637874f59029a6283a65c as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • CMs
  • Publiccms

Affected Vendors

  • Pluck -
  • Publiccms