CVE-2024-51026
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2024-51026 is a newly identified Cross-Site Scripting (XSS) vulnerability affecting the NetAdmin IAM system, version 4.0.30319. The issue lies in the /BalloonSave.ashx endpoint, where an adversary can inject malicious payloads into the Content= field. Successful exploitation of this flaw may lead to the unauthorized execution of malicious scripts within the user's web browser. This can lead to session hijacking, data theft, or other malicious activities. Users are strongly advised to update their NetAdmin IAM systems to a patched version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.