CVE-2024-51135
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Nov 11, 2024
Updated: Nov 12, 2024
CWE ID 79
Summary
CVE-2024-51135 is a newly disclosed vulnerability affecting the DocumentBuilderFactory component in powertac-server version 1.9.0. This XML External Entity (XXE) weakness permits attackers to access confidential data or execute unintended code by sending maliciously crafted XML entities. Successful exploitation could lead to serious security consequences. Users are advised to upgrade to a patched version or apply workarounds to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.