CVE-2024-5829
CVSS 2.0 Score 4.0 of 10 (medium)
Details
Summary
CVE-2024-5829 is a newly disclosed vulnerability affecting smallweigit Avue up to version 3.4.4. This issue lies in an unknown functionality of the avueUeditor component, which can be exploited remotely to execute cross-site scripting (XSS) attacks. The manipulation can lead to code injection and potential data theft or unauthorized actions. The vulnerability has been made public, increasing the risk for exploitation. The identifier for this flaw is VDB-267895, and it's important to note that the code maintainers have stated that rich text functionality is no longer supported.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.