CVE-2024-13034
CVSS 3.1 Score 7.6 of 10 (high)
Details
Published Dec 30, 2024
Updated: Jan 6, 2025
CWE ID 94
CWE ID 79
Summary
CVE-2024-13034 is a recently disclosed vulnerability affecting the code-projects Chat System 1.0. The issue, classified as problematic, is located in the /admin/update_user.php file and stems from a cross-site scripting (XSS) vulnerability. Malicious actors can manipulate the argument name, leading to the injection of malicious scripts. The attack can be initiated remotely, posing a significant security risk. Public disclosure of the exploit increases the likelihood of its utilization in cyberattacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.