CVE-2024-12641
CVSS 3.1 Score 9.6 of 10 (high)
Details
Summary
CVE-2024-12641 is a Reflected Cross-site scripting (XSS) vulnerability affecting TenderDocTransfer, a service provided by Chunghwa Telecom. The application sets up a local web server and offers APIs for interacting with targeted websites. Due to the absence of Cross-Site Request Forgery (CSRF) protection for these APIs, unauthenticated remote attackers can exploit them through phishing techniques to inject malicious JavaScript code into users' browsers. With Node.Js features supported by the web server, an attacker could potentially escalate the vulnerability and run OS commands.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.