CVE-2024-55451

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Dec 16, 2024
Updated: Dec 17, 2024
CWE ID 79

Summary

CVE-2024-55451 is a stored Cross-Site Scripting (XSS) vulnerability affecting UJCMS 9.6.3. This issue stems from inadequate sanitization of embedded attributes in SVG files during upload and viewing. When an authenticated user opens a maliciously crafted SVG file, attackers can inject and execute arbitrary JavaScript code in the context of other backend users' browsers. This could potentially result in the theft of sensitive tokens.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share