CVE-2024-54421

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Dec 16, 2024
CWE ID 352

Summary

CVE-2024-54421 is a Cross-Site Request Forgery (CSRF) vulnerability discovered in the Sanjay Singh Negi Floating Video Player. This issue permits attackers to execute Stored XSS (Cross-Site Scripting) attacks against unsuspecting users. The vulnerability can affect Floating Video Player versions from not available to 1.0. Successful exploitation could lead to the injection of malicious scripts into a user's web browser, potentially resulting in data theft or unauthorized actions. Users are advised to update to the latest version of the Floating Video Player to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share