CVE-2024-46081
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2024-46081 is a Cross-Site Scripting (XSS) vulnerability affecting Scriptcase version 9.10.023 and older. An authenticated user can exploit this flaw by crafting malicious scripts for the To-Do List feature. These scripts are stored and can be triggered by other assigned users on the platform, posing a significant security risk. This vulnerability allows attackers to inject and execute malicious code within the context of the targeted user's session. The potential impact includes unauthorized access, data theft, and system manipulation. Users are urged to update their Scriptcase installation as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Scriptcase
Affected Vendors
- Scriptcase