CVE-2024-5851

CVSS 2.0 Score 4.0 of 10 (medium)

Details

Published Jun 11, 2024
Updated: Jun 13, 2024
CWE ID 80

Summary

CVE-2024-5851 is a newly identified vulnerability affecting playSMS up to version 1.4.7. The issue lies in an unknown function of the /index.php?app=main&inc=feature_schedule&op=list component, specifically the SMS Schedule Handler. The manipulation of argument names or messages can trigger a basic cross-site scripting attack, allowing remote attackers to inject malicious code. Upgrading to version 1.4.8 resolves this issue with patch 7a88920f6b536c6a91512e739bcb4e8adefeed2b. To mitigate this risk, it is strongly recommended that users upgrade the affected component as soon as possible. The identifier for this vulnerability is VDB-267912, and the component maintainer has demonstrated a willingness to promptly address the issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share