CVE-2024-51760

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Nov 9, 2024
Updated: Nov 12, 2024
CWE ID 79

Summary

CVE-2024-51760 is a Cross-Site Scripting (XSS) vulnerability affecting RistrettoApps Dashing Memberships from versions n/a through 1.1. This issue occurs due to improper neutralization of user input during web page generation. Attackers can exploit this vulnerability by injecting malicious scripts into web pages viewed by other users, potentially stealing sensitive information or taking control of their sessions. Users are advised to update to the latest version of Dashing Memberships to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share