CVE-2024-13034

CVSS 3.1 Score 7.6 of 10 (high)

Details

Published Dec 30, 2024
Updated: Jan 6, 2025
CWE ID 94
CWE ID 79

Summary

CVE-2024-13034 is a recently disclosed vulnerability affecting the code-projects Chat System 1.0. The issue, classified as problematic, is located in the /admin/update_user.php file and stems from a cross-site scripting (XSS) vulnerability. Malicious actors can manipulate the argument name, leading to the injection of malicious scripts. The attack can be initiated remotely, posing a significant security risk. Public disclosure of the exploit increases the likelihood of its utilization in cyberattacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share