CVE-2024-46082

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Oct 1, 2024
Updated: Oct 4, 2024
CWE ID 79

Summary

CVE-2024-46082 is a newly disclosed vulnerability that affects Scriptcase version 9.10.023 and older. This issue permits attackers to inject malicious scripts into web pages through the nm_cor.php file. The vulnerability is specifically located in the form and field parameters, making it susceptible to Cross-Site Scripting (XSS) attacks. Successful exploitation could lead to the execution of malicious code in users' browsers, resulting in data theft, session hijacking, or other unauthorized actions. System administrators are strongly urged to update their Scriptcase installations to a patched version as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share