CVE-2024-40124

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Apr 17, 2025
Updated: Apr 18, 2025
CWE ID 79

Summary

CVE-2024-40124 is a newly disclosed vulnerability that affects Pydio Core versions below 8.2.6. The issue involves the New URL Bookmark feature, which is susceptible to Cross-Site Scripting (XSS) attacks. An attacker who successfully exploits this vulnerability can inject malicious scripts into a victim's web browser, potentially leading to unauthorized access or data theft. This can pose a significant risk, especially in enterprise environments where sensitive data is frequently accessed through the affected application. It is strongly recommended that users upgrade to the latest version of Pydio Core to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share