CVE-2024-26313
CVSS 3.1 Score 7.3 of 10 (high)
Details
Published Mar 8, 2024
Summary
CVE-2024-26313 is a stored cross-site scripting (XSS) vulnerability affecting Archer Platform versions 6.x before 6.14 P2 HF2 (6.14.0.2.2). Malicious Archer users with authenticated access can exploit this flaw to inject malicious HTML or JavaScript code into a trusted application data store. When victims access the data store, their web browsers execute the malicious code in the context of the vulnerable application. Versions 6.13.P3 HF1 (6.13.0.3.1) and later have been released to address this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share