CVE-2024-44037
CVSS 3.1 Score 5.9 of 10 (medium)
Details
Summary
CVE-2024-44037 is a newly disclosed Cross-Site Scripting (XSS) vulnerability affecting the MagePeople Team Multipurpose Ticket Booking Manager. The flaw, which permits Stored XSS attacks, lies in the way the application handles user input during web page generation. An attacker can exploit this vulnerability by injecting malicious scripts into a web page, which can then be executed in the context of other users visiting the same page. The issue affects versions of the Multipurpose Ticket Booking Manager from n/a through 4.2.2. Successful exploitation could lead to theft of user data or unauthorized actions in the affected system. It is recommended that users upgrade to the latest version of the software to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.