CVE-2024-5414
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published May 28, 2024
CWE ID 79
Summary
CVE-2024-5414 is a newly identified vulnerability impacting PhpMyBackupPro version 2.3. This issue permits cross-site scripting (XSS) attacks through the application's get_file.php page, specifically the 'view' parameter. An attacker can craft a malicious URL and send it to a victim, potentially gaining access to their session details. This vulnerability poses a significant security risk and should be addressed immediately by updating to a patched version of PhpMyBackupPro.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.