CVE-2024-54774

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Dec 27, 2024
Updated: Dec 28, 2024
CWE ID 79

Summary

CVE-2024-54774 is a newly identified cross-site scripting (XSS) vulnerability affecting Dcat Admin version 2.2.0-beta. This issue resides in the /admin/articles/create path and can be exploited by attackers to inject malicious scripts into web pages viewed by other users. Successful exploitation may result in unauthorized access to user sessions or theft of sensitive data. Users are advised to update their Dcat Admin installations to a patched version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share