CVE-2024-44037

CVSS 3.1 Score 5.9 of 10 (medium)

Details

Published Oct 6, 2024
Updated: Oct 7, 2024
CWE ID 79

Summary

CVE-2024-44037 is a newly disclosed Cross-Site Scripting (XSS) vulnerability affecting the MagePeople Team Multipurpose Ticket Booking Manager. The flaw, which permits Stored XSS attacks, lies in the way the application handles user input during web page generation. An attacker can exploit this vulnerability by injecting malicious scripts into a web page, which can then be executed in the context of other users visiting the same page. The issue affects versions of the Multipurpose Ticket Booking Manager from n/a through 4.2.2. Successful exploitation could lead to theft of user data or unauthorized actions in the affected system. It is recommended that users upgrade to the latest version of the software to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share