CVE-2024-51696

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Nov 9, 2024
Updated: Nov 12, 2024
CWE ID 79

Summary

CVE-2024-51696 is a newly disclosed Cross-Site Scripting (XSS) vulnerability affecting the Benjamin Moody Content Syndication Toolkit Reader. The flaw, which allows Reflected XSS attacks, exists due to improper input neutralization during web page generation. This issue can be exploited by an attacker to inject malicious scripts into web pages viewed by other users, potentially leading to data theft or application takeover. The vulnerability affects Content Syndication Toolkit Reader versions from n/a through 1.5. Users are advised to update to the latest version or contact their vendor for a patch as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share