CVE-2024-8942
CVSS 3.1 Score 8.2 of 10 (high)
Details
Published Sep 25, 2024
Updated: Sep 30, 2024
CWE ID 79
Summary
CVE-2024-8942 is a newly disclosed Cross-Site Scripting (XSS) vulnerability affecting Scriptcase version 9.4.019. The issue stems from insufficient input validation, specifically on the "id_form_msg_title" parameter, as well as other unspecified inputs. This flaw puts users at risk as an attacker can craft a malicious URL and send it to a victim, potentially stealing their credentials upon interaction with the URL.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Scriptcase
Affected Vendors
- Scriptcase