CVE-2024-55342
CVSS 3.1 Score 4.7 of 10 (medium)
Details
Summary
CVE-2024-55342 is a vulnerability affecting Piranha CMS 11.1. This issue allows authenticated attackers to upload malicious PDF files to the /manager/media directory. The PDF files can contain JavaScript code that gets executed in the user's web browser when they open or interact with the file, resulting in a Cross-Site Scripting (XSS) attack. Attackers can exploit this vulnerability to steal sensitive information, conduct unauthorized actions, or install malware on the victim's system. Users are advised to update their Piranha CMS installation as soon as a patch is available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.