CVE-2024-47186
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2024-47186 is a cross-site scripting (XSS) vulnerability affecting Filament, a collection of full-stack components used in Laravel development. Versions from v3.0.0 to v3.2.114 are vulnerable, and the issue lies in the handling of values passed to `ColorColumn` and `ColumnEntry`. If these values contain a specific set of characters that are not valid, attackers can exploit this flaw and inject malicious code, potentially leading to XSS attacks against users who view pages with affected color columns or entries. The vulnerability has been addressed in Filament v3.2.115.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.