CVE-2024-54428
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2024-54428 is a newly disclosed vulnerability that combines Cross-Site Request Forgery (CSRF) and Stored XSS attacks. Affecting the "Add image to Post" feature in versions 0.1 through 0.6, an attacker can exploit this vulnerability to inject malicious code into a user's web session, potentially leading to unauthorized actions or data theft. The CSRF vulnerability enables an attacker to submit unintended commands on behalf of a victim, while the Stored XSS component allows the attacker to leave malicious scripts for future use. This combination significantly increases the severity of the issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.