CVE-2024-12664

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Dec 16, 2024
Updated: Dec 19, 2024
CWE ID 94
CWE ID 79

Summary

CVE-2024-12664 is a recently disclosed vulnerability affecting the Project Task Comment Handler component in ruifang-tech Rebuild 3.8.5. This issue, classified as problematic, enables attackers to execute cross-site scripting (XSS) attacks. The manipulation can be initiated remotely, meaning an attacker does not require access to the victim's system. The vulnerability has been made public, increasing the risk of exploitation. Despite early notification from the security community, the vendor has not yet responded to address this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share