CVE-2024-54399

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Dec 16, 2024
CWE ID 352

Summary

CVE-2024-54399 is a Cross-Site Request Forgery (CSRF) vulnerability affecting CRUDLab's Google Plus Button. An attacker can exploit this issue to perform Stored Cross-Site Scripting (XSS) attacks on unsuspecting users. The CRUDLab Google Plus Button, which ranges from version n/a to 1.0.2, is the affected software. This CSRF-related XSS vulnerability poses a significant security risk and should be addressed promptly by users and administrators.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share