CVE-2024-47093

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Dec 19, 2024
CWE ID 79

Summary

CVE-2024-47093 is a newly identified vulnerability affecting Nagvis before version 1.9.42. This issue involves improper input neutralization, making it possible for attackers to execute Cross-Site Scripting (XSS) attacks. Successful exploitation could allow the attacker to inject malicious scripts into a victim's web browser, potentially leading to unauthorized access to sensitive user data or session hijacking. Users are urged to update their Nagvis installations to the latest version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share