CVE-2024-12641

CVSS 3.1 Score 9.6 of 10 (high)

Details

Published Dec 16, 2024
CWE ID 79

Summary

CVE-2024-12641 is a Reflected Cross-site scripting (XSS) vulnerability affecting TenderDocTransfer, a service provided by Chunghwa Telecom. The application sets up a local web server and offers APIs for interacting with targeted websites. Due to the absence of Cross-Site Request Forgery (CSRF) protection for these APIs, unauthenticated remote attackers can exploit them through phishing techniques to inject malicious JavaScript code into users' browsers. With Node.Js features supported by the web server, an attacker could potentially escalate the vulnerability and run OS commands.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share