CVE-2024-11404
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Summary
CVE-2024-11404 is a serious vulnerability in Django CMS Association's django Filer component. Affecting versions prior to 3.3, this issue allows for unrestricted file uploads with dangerous types and input validation failures. The vulnerability also includes a Basic XSS (Cross-Site Scripting) flaw due to improper neutralization of script-related HTML tags. Attackers can manipulate input data to execute malicious code, leading to potential data theft or unauthorized system access. Users are urged to upgrade to the latest version of django Filer to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.