CVE-2024-54999
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Jan 13, 2025
CWE ID 94
Summary
CVE-2024-54999 is a newly disclosed vulnerability affecting MonicaHQ version 4.1.2. This issue involves a Client-Side Injection (CSI) vulnerability, which can be exploited by attackers through manipulation of the last_name parameter in the General Information module. Successful exploitation allows attackers to execute malicious code or gain unauthorized access to user data, posing a significant security risk. Users are strongly encouraged to update to the latest version of MonicaHQ to mitigate this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.