CVE-2024-55081
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2024-55081 is an XML External Entity (XXE) injection vulnerability identified in the component /datagrip/upload of Chat2DB v0.3.5. This weakness allows attackers to execute arbitrary code by supplying crafted XML inputs. An attacker could exploit this vulnerability to gain unauthorized access, steal sensitive information, or launch other types of attacks. XML data is used to transport and transmit data between different applications, making this a significant security risk. Organizations using Chat2DB version 0.3.5 are urged to apply the necessary patches or upgrades as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.