CVE-2024-12995
CVSS 2.0 Score 4 of 10 (medium)
Details
Published Dec 28, 2024
CWE ID 94
CWE ID 79
Summary
CVE-2024-12995 is a newly disclosed vulnerability affecting the Project Tasks Section component in ruifang-tech Rebuild 3.8.6. This issue lies in an unspecified part of the /project/050-9000000000000001/tasks file, resulting in a cross-site scripting (XSS) vulnerability. Attackers can exploit this remotely by manipulating the argument description. Although the vendor was informed about the disclosure, they have not yet responded or released a patch, leaving affected systems potentially vulnerable to XSS attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.