CVE-2024-42831

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Oct 7, 2024
Updated: Nov 21, 2024
CWE ID 79

Summary

CVE-2024-42831 is a reflected cross-site scripting (XSS) vulnerability affecting Elaine's Realtime CRM Automation v6.18.17. This issue allows malicious actors to inject and execute arbitrary JavaScript code in a user's web browser by crafting a payload and targeting the dialog parameter in wrapper_dialog.php. Successful exploitation could lead to unauthorized data access, manipulation, or theft, as well as potential redirection to malicious sites. Users are advised to update their CRM software to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share