CVE-2024-49379
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Nov 13, 2024
Updated: Nov 15, 2024
CWE ID 79
Summary
CVE-2024-49379 is a reflected cross-site scripting (XSS) vulnerability affecting the login functionality of Umbrel, a home server OS for self-hosting, prior to version 1.2.2. An attacker can exploit this issue by specifying a malicious redirect query parameter, leading to the execution of JavaScript code after the user enters their password and clicks on login. This vulnerability poses a significant risk as it enables attackers to steal user credentials or carry out other malicious activities. The issue has been resolved in version 1.2.2.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.