CVE-2024-55060
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2024-55060 is a newly disclosed cross-site scripting (XSS) vulnerability. This issue lies within the index.php component of Rafed CMS Website version 1.44. Malicious actors can exploit this flaw to inject and execute arbitrary web scripts or HTML code, potentially leading to serious security consequences such as data theft or unauthorized website control. Attackers can deliver the malicious payload through specially crafted input, thereby targeting unsuspecting users visiting the affected website. It is crucial for users running Rafed CMS Website v1.44 to apply the necessary patches or upgrades as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- CMs
Affected Vendors
- Pluck -