CVE-2024-5851
CVSS 2.0 Score 4.0 of 10 (medium)
Details
Summary
CVE-2024-5851 is a newly identified vulnerability affecting playSMS up to version 1.4.7. The issue lies in an unknown function of the /index.php?app=main&inc=feature_schedule&op=list component, specifically the SMS Schedule Handler. The manipulation of argument names or messages can trigger a basic cross-site scripting attack, allowing remote attackers to inject malicious code. Upgrading to version 1.4.8 resolves this issue with patch 7a88920f6b536c6a91512e739bcb4e8adefeed2b. To mitigate this risk, it is strongly recommended that users upgrade the affected component as soon as possible. The identifier for this vulnerability is VDB-267912, and the component maintainer has demonstrated a willingness to promptly address the issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.