CVE-2024-54451
CVSS 3.1 Score 4.8 of 10 (medium)
Details
Summary
CVE-2024-54451 is a cross-site scripting (XSS) vulnerability affecting the graphicCustomization.do page in Kurmi Provisioning Suite versions prior to 7.9.0.38, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15. This vulnerability allows authenticated system administrators to inject arbitrary web scripts or HTML into the COMPONENT_fields(htmlTitle) field. The injected code is rendered on other pages of the application, potentially affecting all users if graphical customization has been activated by a super-administrator. This issue could lead to unintended execution of malicious scripts or unauthorized access to sensitive information.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.