CVE-2024-39311
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2024-39311 is a cross-site scripting (XSS) vulnerability affecting versions prior to 10.0.1 of Publify, a self-hosted web publishing platform on Rails. This issue allows publishers to execute malicious scripts on an administrator's browser through the redirect functionality. Exploitation requires the administrator to click a maliciously crafted link, potentially allowing an attacker to hide their payload using HTML or other encodings. The successful exploitation could enable an attacker to escalate their privileges and gain administrative access. Version 10.0.1 of Publify and version 10.0.2 of the `publify_core` rubygem have been released to address this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Publify
Affected Vendors
- Publify