CVE-2024-45967

CVSS 3.1 Score 4.7 of 10 (medium)

Details

Published Oct 1, 2024
Updated: Oct 4, 2024
CWE ID 79

Summary

CVE-2024-45967 refers to a Cross-Site Scripting (XSS) vulnerability affecting Pagekit 1.0.18. This issue allows malicious actors to inject malicious scripts into a website's admin interface, specifically in the "index.php/admin/site/widget" endpoint of the application. Successful exploitation can lead to unauthorized data access, unintended modification of data, or even takeover of the affected user's account. Users are strongly advised to upgrade to a patched version of Pagekit as soon as possible to prevent potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share