CVE-2024-29918
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2024-29918 is a Cross-site Scripting (XSS) vulnerability affecting Survey Maker's Web page generation process from version 4.0.6 and prior. The flaw, named Reflected XSS, allows attackers to inject malicious scripts into web pages viewed by other users. This can lead to theft of user data, session hijacking, and other malicious activities. Attackers can exploit this vulnerability by crafting specially crafted input that is reflected back to users in the web page. Users are strongly encouraged to update their Survey Maker installations to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.