CVE-2024-47002
CVSS 3.1 Score 8.7 of 10 (high)
Details
Summary
CVE-2024-47002 is a html code injection vulnerability discovered in Observium CE 24.4.13528's vlan management feature. Maliciously crafted HTTP requests can exploit this weakness, allowing an attacker to inject arbitrary html code. An authenticated user would unwittingly activate the malicious code by clicking a link provided by the attacker. This vulnerability poses a potential security risk, as it allows attackers to manipulate the Observium CE interface and potentially gain unauthorized access to sensitive information. Users are encouraged to update their software to the latest version as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- CE