CVE-2024-47376

CVSS 3.1 Score 5.9 of 10 (medium)

Details

Published Oct 5, 2024
Updated: Oct 7, 2024
CWE ID 79

Summary

CVE-2024-47376 is a newly identified Cross-Site Scripting (XSS) vulnerability that affects the Tribulant Slideshow Gallery. The flaw, located in the web page generation process, permits attackers to inject malicious scripts into the slideshow, which can be stored and subsequently executed in users' browsers. This vulnerability poses a serious security risk, as attackers can steal sensitive data, manipulate web pages, or install malware on affected systems. The issue has been reported to impact versions 1.8.3 and below of the Tribulant Slideshow Gallery. Users are strongly advised to apply the necessary patches or upgrades to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share