CVE-2024-40124
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2024-40124 is a newly disclosed vulnerability that affects Pydio Core versions below 8.2.6. The issue involves the New URL Bookmark feature, which is susceptible to Cross-Site Scripting (XSS) attacks. An attacker who successfully exploits this vulnerability can inject malicious scripts into a victim's web browser, potentially leading to unauthorized access or data theft. This can pose a significant risk, especially in enterprise environments where sensitive data is frequently accessed through the affected application. It is strongly recommended that users upgrade to the latest version of Pydio Core to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- CORE
Affected Vendors
- JET Charge Pty Ltd