CVE-2024-9266

CVSS 3.1 Score 4.7 of 10 (medium)

Details

Published Oct 3, 2024
Updated: Oct 4, 2024
CWE ID 601

Summary

CVE-2024-9266 is a newly disclosed vulnerability affecting the Express web application framework. This Open Redirect vulnerability lies in the use of the Express Response object. An attacker can exploit this weakness to redirect users to malicious websites, potentially leading to phishing or data theft. The issue impacts Express versions from 3.4.5 to 4.0.0, making it essential for developers using these versions to apply the necessary patches to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share