CVE-2024-52597

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Nov 20, 2024
Updated: Nov 21, 2024
CWE ID 79
CWE ID 80

Summary

CVE-2024-52597 is a stored cross-site scripting vulnerability affecting versions prior to 5.4.1 of the 2FAuth web application. Malicious SVG images, which are accepted by the application, can contain JavaScript code that is executed when accessed. An attacker can upload such an image and lure a victim to it, leading to session compromise and unauthorized access to tokens. The vulnerability is due to improper headers in the direct access to uploaded SVGs. Version 5.4.1 includes a patch to address this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share