CVE-2024-55060

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Mar 13, 2025
Updated: Apr 3, 2025
CWE ID 79

Summary

CVE-2024-55060 is a newly disclosed cross-site scripting (XSS) vulnerability. This issue lies within the index.php component of Rafed CMS Website version 1.44. Malicious actors can exploit this flaw to inject and execute arbitrary web scripts or HTML code, potentially leading to serious security consequences such as data theft or unauthorized website control. Attackers can deliver the malicious payload through specially crafted input, thereby targeting unsuspecting users visiting the affected website. It is crucial for users running Rafed CMS Website v1.44 to apply the necessary patches or upgrades as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share