CVE-2024-1749

CVSS 2.0 Score 3.3 of 10 (low)

Details

Published Feb 22, 2024
Updated: May 17, 2024
CWE ID 79

Summary

CVE-2024-1749 is a newly disclosed vulnerability affecting Bdtask Bhojon Best Restaurant Management Software version 2.9. The issue lies in the processing of the /dashboard/message component's Title argument, which can be exploited through cross-site scripting (XSS) attacks. This vulnerability can be triggered remotely, allowing an attacker to inject malicious scripts into a user's browser. Though the exact extent of the affected user base is unknown, the exploit has been made public, raising concerns for potential widespread abuse. The associated identifier for this vulnerability is VDB-254531. Regrettably, efforts to notify the vendor of this issue have yielded no response.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share