CVE-2024-40509
CVSS 3.1 Score 7.3 of 10 (high)
Details
Published Sep 27, 2024
Updated: Sep 30, 2024
CWE ID 79
Summary
CVE-2024-40509 is a newly identified Cross-Site Scripting (XSS) vulnerability affecting the openPetra v.2023.02 software. An attacker can exploit this weakness by injecting malicious scripts into the serverMFinDev.asmx function, thereby gaining unauthorized access to sensitive information on the affected system. This issue poses a significant risk, as it can lead to data theft or unintended system actions. Users of openPetra v.2023.02 are advised to apply the necessary patches or updates as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.