CVE-2024-11404

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Nov 20, 2024
Updated: Nov 21, 2024
CWE ID 434
CWE ID 80
CWE ID 20

Summary

CVE-2024-11404 is a serious vulnerability in Django CMS Association's django Filer component. Affecting versions prior to 3.3, this issue allows for unrestricted file uploads with dangerous types and input validation failures. The vulnerability also includes a Basic XSS (Cross-Site Scripting) flaw due to improper neutralization of script-related HTML tags. Attackers can manipulate input data to execute malicious code, leading to potential data theft or unauthorized system access. Users are urged to upgrade to the latest version of django Filer to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share