CVE-2024-54853

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Feb 5, 2025
Updated: Feb 6, 2025
CWE ID 79

Summary

CVE-2024-54853 is a Stored Cross-Site Scripting (XSS) vulnerability that affects Skybox Change Manager versions 13.2.170 and older. This issue allows remote authenticated users to inject malicious code into specific fields, which is then executed in the browser of unsuspecting victims. By exploiting this vulnerability, attackers can steal sensitive information or take control of the victim's session. This can lead to unauthorized access or other malicious activities. It is crucial for organizations using the affected version to apply the available patch or upgrade to a newer version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share