CVE-2024-9572

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Oct 7, 2024
Updated: Oct 8, 2024
CWE ID 79

Summary

CVE-2024-9572 is a Cross-Site Scripting (XSS) vulnerability affecting SOPlanning versions below 1.45. The issue stems from insufficient input validation in the /soplanning/www/process/groupe_save.php file, specifically in the groupe_id parameter. An attacker can exploit this flaw by sending a crafted query to an authenticated user, resulting in the theft of their session details. This vulnerability poses a serious risk to users, as session hijacking could lead to unauthorized access and data compromise.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share