CVE-2024-47093
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Dec 19, 2024
CWE ID 79
Summary
CVE-2024-47093 is a newly identified vulnerability affecting Nagvis before version 1.9.42. This issue involves improper input neutralization, making it possible for attackers to execute Cross-Site Scripting (XSS) attacks. Successful exploitation could allow the attacker to inject malicious scripts into a victim's web browser, potentially leading to unauthorized access to sensitive user data or session hijacking. Users are urged to update their Nagvis installations to the latest version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- NagVis
Affected Vendors
- Nagvis