CVE-2024-5520

CVSS 3.1 Score 6.4 of 10 (medium)

Details

Published May 30, 2024
CWE ID 79

Summary

CVE-2024-5520 is a vulnerability found in Alkacon's OpenCMS version 16, which allows users with sufficient privileges to execute malicious JavaScript code by inserting it into the "title" field of web pages through the admin panel. This vulnerability is categorized as Cross-Site Scripting (CWE-79) and has a base severity rating of MEDIUM. The exploitability score is 3.1, indicating a moderate level of ease for attackers to exploit this vulnerability. The impact score is 2.7, with low integrity and confidentiality impacts. Remediation for this vulnerability involves updating to a patched version of OpenCMS and ensuring proper input validation to prevent script injection attacks.

Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future

Note: This is just a basic overview providing quick insights into CVE-2024-5520 information. Gain full access to comprehensive CVE data, third party vulnerabilities, compromised credentials and more with Recorded Future
  • Gain complete coverage of your cyber, third party, and physical attack surface
  • Proactively mitigate threats before they turn into costly attacks
  • Make fast, effective, data-driven decisions