CVE-2024-12783
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Dec 19, 2024
Updated: Jan 10, 2025
CWE ID 94
CWE ID 79
Summary
CVE-2024-12783 is a recently disclosed vulnerability affecting the Vehicle Management System 1.0. This issue involves the processing of the file /billaction.php, and the manipulation of the argument "extra-cost" can lead to cross-site scripting. This vulnerability can be exploited remotely, allowing attackers to inject malicious scripts into unsuspecting users' browsers. The exploit for this issue has been made public, making it a significant security concern for organizations using this software.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.