CVE-2024-45985

CVSS 3.1 Score 4.7 of 10 (medium)

Details

Published Sep 26, 2024
Updated: Sep 30, 2024
CWE ID 79

Summary

CVE-2024-45985 is a newly discovered Cross Site Scripting (XSS) vulnerability. The issue lies in the update_contact.php file of the Blood Bank and Donation Management System version 1.0. An attacker can exploit this vulnerability by injecting malicious scripts through the name parameter in the update_contact.php. Successful exploitation could lead to unintended execution of malicious code in a user's browser, potentially resulting in data theft or unauthorized system access. This vulnerability poses a significant risk and requires immediate attention and patching from system administrators.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share