CVE-2024-48662
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Jan 27, 2025
Updated: Jan 28, 2025
CWE ID 79
Summary
CVE-2024-48662 is a Cross-Site Scripting (XSS) vulnerability affecting AdGuard Application versions 7.18.1 (4778) and earlier. An attacker can exploit this flaw by injecting a malicious payload into the fontMatrix component, allowing the execution of arbitrary code on a victim's browser during a man-in-the-middle attack. This vulnerability can potentially lead to data theft, session hijacking, or other forms of unauthorized access. Users are encouraged to update their AdGuard Application to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share