CVE-2024-53408
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Feb 27, 2025
Updated: Feb 28, 2025
CWE ID 79
Summary
CVE-2024-53408 is a newly identified cross-site scripting (XSS) vulnerability affecting the AVE System Web Client version 2.1.131.13992. Malicious actors can exploit this weakness to inject malicious scripts into a victim's web browser, potentially leading to unauthorized access to sensitive information or system takeover. Successful exploitation relies on the victim visiting a specially crafted web page. Users are advised to update their software promptly to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- WebClient