CVE-2024-45985
CVSS 3.1 Score 4.7 of 10 (medium)
Details
Summary
CVE-2024-45985 is a newly discovered Cross Site Scripting (XSS) vulnerability. The issue lies in the update_contact.php file of the Blood Bank and Donation Management System version 1.0. An attacker can exploit this vulnerability by injecting malicious scripts through the name parameter in the update_contact.php. Successful exploitation could lead to unintended execution of malicious code in a user's browser, potentially resulting in data theft or unauthorized system access. This vulnerability poses a significant risk and requires immediate attention and patching from system administrators.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.