CVE-2024-12930
CVSS 2.0 Score 4.0 of 10 (medium)
Details
Summary
CVE-2024-12930 is a newly identified vulnerability affecting the Simple Admin Panel version 1.0. The issue stems from the way the script processes the file addCatController.php, where the argument c_name can be manipulated. This manipulation results in cross-site scripting (XSS), which can be exploited remotely to inject malicious code into a user's web browser and potentially gain unauthorized access to sensitive information. This vulnerability poses a significant security risk and should be addressed promptly by updating to a patched version of the Simple Admin Panel.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Code Projects