CVE-2024-56115
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Dec 18, 2024
Updated: Dec 31, 2024
CWE ID 79
Summary
CVE-2024-56115 is a newly disclosed vulnerability affecting Amiro.CMS versions prior to 7.8.4. This issue arises from insufficient neutralization of special elements, creating an opportunity for remote attackers to execute Cross-Site Scripting (XSS) attacks. By injecting malicious code into a web page viewed by other users, an attacker can steal sensitive information, manipulate user interactions, or install malware. Upgrading to a patched version is strongly advised to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.