CVE-2024-41515
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2024-41515 is a reflected cross-site scripting (XSS) vulnerability affecting the "ccHandlerResource.ashx" component in CADClick versions prior to 1.11.0. An attacker can exploit this flaw by injecting malicious web scripts or HTML code into the "res_url" parameter, which is then reflected in the response to the victim's browser. Successful exploitation could result in unauthorized access to the victim's session or sensitive information, or even the installation of malware. Users are advised to update their CADClick installations to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.