CVE-2024-8413
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2024-8413 identifies a Cross-Site Scripting (XSS) vulnerability present in the action parameter of index.php within the Raspcontrol codebase and its forks. This vulnerability allows attackers to craft malicious JavaScript payloads that can partially hijack the session details of authenticated users. Affected products include those based on the Raspcontrol repository, such as those found at https://github.com/Bioshox/Raspcontrol and https://github.com/harmon25/raspcontrol. Remediation involves sanitizing user input to prevent execution of untrusted scripts. Given its medium severity rating, organizations should address this vulnerability promptly to mitigate potential session hijacking risks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.