CVE-2024-54451

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Dec 27, 2024
Updated: Dec 28, 2024
CWE ID 79

Summary

CVE-2024-54451 is a cross-site scripting (XSS) vulnerability affecting the graphicCustomization.do page in Kurmi Provisioning Suite versions prior to 7.9.0.38, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15. This vulnerability allows authenticated system administrators to inject arbitrary web scripts or HTML into the COMPONENT_fields(htmlTitle) field. The injected code is rendered on other pages of the application, potentially affecting all users if graphical customization has been activated by a super-administrator. This issue could lead to unintended execution of malicious scripts or unauthorized access to sensitive information.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share