CVE-2024-9291

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Sep 27, 2024
Updated: Oct 7, 2024
CWE ID 79

Summary

CVE-2024-9291 is a newly discovered vulnerability affecting the kalvinGit kvf-admin up to f12a94dc1ebb7d1c51ee978a85e4c7ed75c620ff. This issue lies within an unknown function of the /ueditor/upload file in the XML File Handler component. The vulnerability allows attackers to execute cross-site scripting by manipulating the upfile argument. The exploit can be launched remotely, and the public disclosure of the vulnerability increases the risk. The project uses a rolling release model for continuous delivery, making it difficult to determine affected and updated versions. Regrettably, the GitHub repository has not been updated in over two years.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share