CVE-2024-5413
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published May 28, 2024
CWE ID 79
Summary
CVE-2024-5413 is a newly discovered vulnerability in PhpMyBackupPro version 2.3. This issue permits Cross-Site Scripting (XSS) attacks through the /phpmybackuppro/scheduled.php page, affecting all parameters. An attacker can exploit this vulnerability by crafting a malicious URL and sending it to a victim, potentially gaining access to their session details. This security flaw poses a significant risk and requires immediate attention from PhpMyBackupPro users to update their software to a secure version.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.