CVE-2024-9571

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Oct 7, 2024
Updated: Oct 8, 2024
CWE ID 79

Summary

CVE-2024-9571 is a Cross-Site Scripting (XSS) vulnerability affecting SOPlanning versions below 1.45. The issue stems from a lack of sufficient input validation in the /soplanning/www/process/xajax_server.php file, which exposes multiple parameters to this concern. Maliciously crafted queries can be sent to authenticated users, leading to a partial takeover of their browser sessions by an attacker. This could potentially result in data theft or further exploitation. Users are strongly advised to update to the latest version of SOPlanning to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share