CVE-2024-7644

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Aug 12, 2024
Updated: Sep 9, 2024
CWE ID 79

Summary

CVE-2024-7644 is a recently disclosed vulnerability affecting the SourceCodester Leads Manager Tool 1.0. The issue lies within the Add Leads Handler component and specifically the /endpoint/add-leads.php file. This vulnerability permits cross-site scripting (XSS) attacks, where an attacker can manipulate the leads_name/phone_number argument. The exploit can be executed remotely, making it a significant threat. The vulnerability has been made public, increasing the risk of potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share