CVE-2024-56060

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Jan 2, 2025
CWE ID 79

Summary

CVE-2024-56060 is a Cross-site Scripting (XSS) vulnerability affecting HTML Forms, specifically in their input handling during web page generation. This issue permits attackers to inject malicious scripts into web pages viewed by other users, potentially leading to data theft or unauthorized system access. The affected versions range from n/a to 1.4.1. Users are urged to update their HTML Forms software to mitigate this risk and prevent potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share