CVE-2024-52441

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Nov 20, 2024
Updated: Nov 21, 2024
CWE ID 1321

Summary

CVE-2024-52441 is a Prototype Pollution vulnerability affecting Rajesh Thanoch Quick Learn. The issue enables Object Injection due to improperly controlled modification of object prototype attributes. Quick Learn versions from n/a to 1.0.1 are susceptible to this vulnerability, which can potentially lead to arbitrary code execution or data exposure. Attackers can exploit this flaw by manipulating the target object's prototype, resulting in unexpected and potentially malicious behavior. This vulnerability underscores the importance of secure coding practices and keeping software up to date to mitigate such risks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share