CVE-2024-12665
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Dec 16, 2024
Updated: Dec 19, 2024
CWE ID 94
CWE ID 79
Summary
CVE-2024-12665 is a newly disclosed vulnerability in ruifang-tech Rebuild 3.8.5. This issue, classified as problematic, affects an unidentified function of the Task Comment Attachment Upload component. The manipulation of this function results in cross-site scripting, allowing attackers to inject malicious code into web pages viewed by other users. The exploit is publicly available, increasing the risk of remote attacks. Despite early contact, the vendor has not responded to the disclosure.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share