CVE-2024-51026

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Nov 11, 2024
Updated: Nov 12, 2024
CWE ID 79

Summary

CVE-2024-51026 is a newly identified Cross-Site Scripting (XSS) vulnerability affecting the NetAdmin IAM system, version 4.0.30319. The issue lies in the /BalloonSave.ashx endpoint, where an adversary can inject malicious payloads into the Content= field. Successful exploitation of this flaw may lead to the unauthorized execution of malicious scripts within the user's web browser. This can lead to session hijacking, data theft, or other malicious activities. Users are strongly advised to update their NetAdmin IAM systems to a patched version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share