CVE-2024-12842

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Dec 20, 2024
Updated: Dec 24, 2024
CWE ID 94
CWE ID 79

Summary

CVE-2024-12842 is a newly disclosed vulnerability affecting Emlog Pro versions up to 2.4.1. The issue lies within the /admin/user.php file, and it involves manipulation of the argument keyword. This vulnerability leads to Cross-Site Scripting (XSS), allowing remote attackers to inject malicious code into a user's browser. The exploit for this issue has been made public, increasing the potential risk for affected systems.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share