CVE-2024-26313

CVSS 3.1 Score 7.3 of 10 (high)

Details

Published Mar 8, 2024

Summary

CVE-2024-26313 is a stored cross-site scripting (XSS) vulnerability affecting Archer Platform versions 6.x before 6.14 P2 HF2 (6.14.0.2.2). Malicious Archer users with authenticated access can exploit this flaw to inject malicious HTML or JavaScript code into a trusted application data store. When victims access the data store, their web browsers execute the malicious code in the context of the vulnerable application. Versions 6.13.P3 HF1 (6.13.0.3.1) and later have been released to address this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share