CVE-2024-52947
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2024-52947 is a newly disclosed cross-site scripting (XSS) vulnerability affecting LemonLDAP::NG versions prior to 2.20.1. An attacker can exploit this weakness by injecting arbitrary web scripts or HTML code into the url parameter of the upgrade session confirmation page (upgradeSession / forceUpgrade). This vulnerability is particularly concerning as it can be exploited remotely, and the "Upgrade session" plugin must be enabled by an administrator for the attack to succeed. Successful exploitation could lead to data theft or unauthorized system access. It is strongly recommended that users upgrade to LemonLDAP::NG version 2.20.1 as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.