CVE-2024-54999

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Jan 13, 2025
CWE ID 94

Summary

CVE-2024-54999 is a newly disclosed vulnerability affecting MonicaHQ version 4.1.2. This issue involves a Client-Side Injection (CSI) vulnerability, which can be exploited by attackers through manipulation of the last_name parameter in the General Information module. Successful exploitation allows attackers to execute malicious code or gain unauthorized access to user data, posing a significant security risk. Users are strongly encouraged to update to the latest version of MonicaHQ to mitigate this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share