CVE-2024-25936
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Mar 15, 2024
CWE ID 79
Summary
CVE-2024-25936 is a Cross-site Scripting (XSS) vulnerability affecting SoundCloud's Shortcode function, from versions n/a through 4.0.1. Hackers can exploit this flaw to inject malicious scripts into unsuspecting users' browsers, potentially stealing sensitive information or taking control of their accounts. The vulnerability exists due to improper neutralization of user-supplied input during the creation of SoundCloud Shortcode web pages. SoundCloud users and developers are advised to upgrade to the latest version of the software to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share