CVE-2024-12930

CVSS 2.0 Score 4.0 of 10 (medium)

Details

Published Dec 26, 2024
Updated: Dec 27, 2024
CWE ID 94
CWE ID 79

Summary

CVE-2024-12930 is a newly identified vulnerability affecting the Simple Admin Panel version 1.0. The issue stems from the way the script processes the file addCatController.php, where the argument c_name can be manipulated. This manipulation results in cross-site scripting (XSS), which can be exploited remotely to inject malicious code into a user's web browser and potentially gain unauthorized access to sensitive information. This vulnerability poses a significant security risk and should be addressed promptly by updating to a patched version of the Simple Admin Panel.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share