CVE-2024-2070
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Mar 1, 2024
Updated: Dec 17, 2024
CWE ID 362
Summary
CVE-2024-2070 is a newly disclosed vulnerability affecting the SourceCodester FAQ Management System version 1.0. This issue lies in an unknown functionality of the file /endpoint/add-faq.php, making it susceptible to cross-site scripting (XSS) attacks. Perpetrators can exploit this remotely by manipulating the question/answer argument. The exploit has been made public, increasing the risk of this vulnerability being exploited in the wild. The Vulnerability Database has assigned the identifier VDB-255385 to this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.