CVE-2024-12476
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Jan 17, 2025
CWE ID 611
Summary
CVE-2024-12476 represents a newly identified vulnerability, classified as CWE-611: Improper Restriction of XML External Entity References. This issue poses a significant threat, enabling unauthorized data disclosure, impairing workstation integrity, and potentially allowing remote code execution. The vulnerability arises when a specific crafted XML file is imported into the Web Designer configuration tool. This weakness could enable attackers to gain unauthorized access and manipulate data on the compromised computer.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.