CVE-2024-40511

CVSS 3.1 Score 7.3 of 10 (high)

Details

Published Sep 27, 2024
Updated: Sep 30, 2024
CWE ID 79

Summary

CVE-2024-40511 denotes a Cross-Site Scripting (XSS) vulnerability discovered in openPetra v.2023.02. This issue allows remote attackers to inject malicious scripts into the serverMServerAdmin.asmx function, potentially leading to the theft of sensitive information. An attacker could manipulate this weakness to gain unauthorized access to data or perform actions on behalf of the targeted user. The consequences could range from information disclosure to more severe threats such as account takeover or data modification. Organizations using openPetra v.2023.02 are advised to apply available patches or updates to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share