CVE-2024-39311

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Mar 28, 2025
Updated: Apr 14, 2025
CWE ID 79

Summary

CVE-2024-39311 is a cross-site scripting (XSS) vulnerability affecting versions prior to 10.0.1 of Publify, a self-hosted web publishing platform on Rails. This issue allows publishers to execute malicious scripts on an administrator's browser through the redirect functionality. Exploitation requires the administrator to click a maliciously crafted link, potentially allowing an attacker to hide their payload using HTML or other encodings. The successful exploitation could enable an attacker to escalate their privileges and gain administrative access. Version 10.0.1 of Publify and version 10.0.2 of the `publify_core` rubygem have been released to address this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share