CVE-2024-12991

CVSS 3.1 Score 3.5 of 10 (low)

Details

Published Dec 27, 2024
CWE ID 94
CWE ID 79

Summary

CVE-2024-12991 is a newly disclosed cross-site scripting (XSS) vulnerability in Beijing Longda Jushang Technology's DBShop商城系统 3.3 Release 231225. The issue is located in the /home-order file, which becomes vulnerable when the argument orderStatus is manipulated with the input %22%3E%3Csvg%20onload=alert(5888)%3E. This XSS vulnerability allows remote attackers to inject malicious scripts, potentially stealing sensitive user data or taking control of user sessions. Despite early notification to the vendor, they have not responded or taken any action to address this publicly known risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share