CVE-2024-8644
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Sep 27, 2024
Updated: Oct 4, 2024
CWE ID 312
CWE ID 315
Summary
CVE-2024-8644 is a vulnerability affecting Oceanic Software's ValeApp before version 2.0.0. The issue involves the cleartext storage of sensitive information in a cookie, making it susceptible to protocol manipulation and JSON hijacking, also known as JavaScript hijacking. An attacker can exploit this vulnerability by gaining unauthorized access to sensitive data through manipulation of the affected cookie. This vulnerability poses a significant risk to users as it allows an attacker to hijack sessions and potentially gain control over user accounts.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.