CVE-2024-8644

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Sep 27, 2024
Updated: Oct 4, 2024
CWE ID 312
CWE ID 315

Summary

CVE-2024-8644 is a vulnerability affecting Oceanic Software's ValeApp before version 2.0.0. The issue involves the cleartext storage of sensitive information in a cookie, making it susceptible to protocol manipulation and JSON hijacking, also known as JavaScript hijacking. An attacker can exploit this vulnerability by gaining unauthorized access to sensitive data through manipulation of the affected cookie. This vulnerability poses a significant risk to users as it allows an attacker to hijack sessions and potentially gain control over user accounts.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share