CVE-2024-56025

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Jan 2, 2025
CWE ID 79

Summary

CVE-2024-56025 is a Cross-site Scripting (XSS) vulnerability affecting AdWork Media's EZ Content Locker from an undisclosed version up to 3.0. Malicious scripts can be injected into web pages generated by the software, posing a threat to users. The vulnerability arises due to improper neutralization of user input, enabling attackers to execute malicious code in the context of the affected site. Successful exploitation could lead to data theft or unauthorized actions. Users are advised to update their EZ Content Locker to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share