CVE-2024-51830

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Nov 19, 2024
CWE ID 79

Summary

CVE-2024-51830 is a Cross-site Scripting (XSS) vulnerability affecting the Fazilatunnesa News Ticker, versions from n/a to 1.0. An attacker can exploit this issue by injecting malicious scripts during web page generation. The vulnerability allows for Stored XSS, meaning the injected code remains active even after the initial page load, posing a significant threat to users. Successful exploitation could result in data theft, session hijacking, or even complete system takeover. Users are urged to update their News Ticker software to a patched version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share