CVE-2024-40512

CVSS 3.1 Score 7.3 of 10 (high)

Details

Published Sep 27, 2024
Updated: Sep 30, 2024
CWE ID 79

Summary

CVE-2024-40512 is a Cross-Site Scripting (XSS) vulnerability affecting the openPetra v.2023.02 software. Attackers can exploit this flaw by injecting malicious code into the serverMReporting.asmx function, resulting in the unintended execution of the attacker's script within a user's web browser session. Successful exploitation allows the attacker to steal sensitive information from the affected system, posing a serious security risk for organizations using this software. It is crucial that users apply the necessary patches or upgrades to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share