CVE-2024-43795

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Oct 2, 2024
Updated: Oct 31, 2024
CWE ID 79

Summary

CVE-2024-43795 is a reflected cross-site scripting (XSS) vulnerability affecting the login functionality of OpenC3 COSMOS in its Open Source Edition. This vulnerability allows an attacker to inject malicious code into a webpage viewed by other users, potentially leading to unauthorized access or data theft. The vulnerability has been addressed in version 5.19.0, and it's essential for OpenC3 COSMOS users of the open-source edition to upgrade as soon as possible to mitigate this risk. It's important to note that the enterprise edition of OpenC3 COSMOS is not affected by this CVE.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share