CVE-2024-46494

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Apr 7, 2025
Updated: Apr 23, 2025
CWE ID 79

Summary

CVE-2024-46494 is a newly disclosed cross-site scripting (XSS) vulnerability. Affecting Typecho version 1.2.1, this issue allows malicious actors to inject arbitrary web scripts or HTML into a Name parameter under a comment for an Article. Successful exploitation could lead to unintended execution of malicious code in users' browsers, potentially resulting in data theft or unauthorized access. Users are urged to update their Typecho installations to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share