CVE-2024-9969
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2024-9969 affects NewType WebEIP version 3.0, which has a vulnerability due to improper validation of user input, allowing remote attackers to execute Reflected Cross-site Scripting (XSS) attacks with low privileges. The product is no longer maintained, and users are advised to upgrade to a new product as a remediation measure. The vulnerability has an exploitability score of 2.3 and is rated with a medium severity level of 5.4 on the CVSS scale, indicating that while it poses some risk, user interaction is required for exploitation. The integrity and confidentiality impacts are assessed as low, with no availability impact noted. Organizations using this affected product should take immediate action to mitigate potential risks associated with this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.