CVE-2024-57097
CVSS 3.1 Score 4.8 of 10 (medium)
Details
Published Feb 3, 2025
CWE ID 79
Summary
CVE-2024-57097 is a newly disclosed vulnerability affecting ClassCMS version 4.8. This issue involves Cross-Site Scripting (XSS), which allows an attacker to inject malicious scripts into a web page viewed by other users. Particularly, the vulnerability lies in the class/admin/channel.php file, making it a significant risk for administrators using this version of ClassCMS. Successful exploitation could lead to data theft, account takeover, or other forms of unauthorized access. Users are strongly advised to update to a patched version to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share