CVE-2024-8413

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Sep 4, 2024
Updated: Sep 5, 2024
CWE ID 79

Summary

CVE-2024-8413 identifies a Cross-Site Scripting (XSS) vulnerability present in the action parameter of index.php within the Raspcontrol codebase and its forks. This vulnerability allows attackers to craft malicious JavaScript payloads that can partially hijack the session details of authenticated users. Affected products include those based on the Raspcontrol repository, such as those found at https://github.com/Bioshox/Raspcontrol and https://github.com/harmon25/raspcontrol. Remediation involves sanitizing user input to prevent execution of untrusted scripts. Given its medium severity rating, organizations should address this vulnerability promptly to mitigate potential session hijacking risks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share