CVE-2024-51835

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Nov 19, 2024
CWE ID 79

Summary

CVE-2024-51835 is a Cross-site Scripting (XSS) vulnerability affecting the OpenCart Product Display module from an unknown version to 1.0. This issue arises due to improper neutralization of user input during web page generation. An attacker can exploit this vulnerability by injecting malicious scripts into the product display, allowing them to execute arbitrary code in the context of the affected website. The consequence could lead to sensitive data theft or unauthorized account access, posing a significant risk to organizations using the vulnerable OpenCart Product Display module. It is essential to apply the necessary patches or updates to mitigate this vulnerability and protect against potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share