CVE-2024-41515

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Oct 4, 2024
Updated: Oct 7, 2024
CWE ID 79

Summary

CVE-2024-41515 is a reflected cross-site scripting (XSS) vulnerability affecting the "ccHandlerResource.ashx" component in CADClick versions prior to 1.11.0. An attacker can exploit this flaw by injecting malicious web scripts or HTML code into the "res_url" parameter, which is then reflected in the response to the victim's browser. Successful exploitation could result in unauthorized access to the victim's session or sensitive information, or even the installation of malware. Users are advised to update their CADClick installations to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share