CVE-2024-12844
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Dec 20, 2024
Updated: Jan 7, 2025
CWE ID 94
CWE ID 79
Summary
CVE-2024-12844 is a newly disclosed vulnerability affecting Emlog Pro versions up to 2.4.1. This issue lies within an unidentified function in the /admin/store.php file, where a cross-site scripting (XSS) vulnerability arises due to the manipulation of the argument tag. An attacker can exploit this remotely, potentially launching malicious code on victims' systems. The exploit for this vulnerability has already been made public, increasing the risk for potential attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Emlog
Affected Vendors
- EM Log