CVE-2024-9807
CVSS 3.1 Score 4.8 of 10 (medium)
Details
Summary
CVE-2024-9807 is a newly discovered vulnerability affecting Craig Rodway Classroombookings 2.8.7. This issue lies in the processing of the /sessions file within the Session Page component. An attacker can exploit this cross-site scripting (XSS) vulnerability by manipulating the Name argument, gaining the ability to inject malicious code. Remote attacks are possible, making this a significant security concern. To mitigate the risk, it is recommended to upgrade to version 2.8.8 as soon as possible. The project maintainer promptly responded to the disclosure, demonstrating a professional and responsive approach.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.