CVE-2024-48170

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Feb 10, 2025
Updated: Feb 18, 2025
CWE ID 79

Summary

CVE-2024-48170 is a Cross-Site Scripting (XSS) vulnerability affecting PHPGurukul Small CRM version 3.0. An attacker can exploit this issue by injecting a malicious payload into the name field of the profile.php page, potentially stealing user session cookies or executing malicious scripts in the browser of unsuspecting victims. This vulnerability poses a significant risk to organizations using this CRM software and requires immediate patching to mitigate the threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share