CVE-2024-10927
CVSS 2.0 Score 4.0 of 10 (medium)
Details
Summary
CVE-2024-10927 is a newly disclosed vulnerability affecting MonoCMS up to version 20240528. This issue, located in the Account Information Page's /monofiles/account.php file, is classified as problematic. The vulnerability stems from a flaw in an unknown function, where manipulation of the userid argument results in cross-site scripting (XSS). Attacks can be executed remotely, increasing the risk for exploitation. Unfortunately, the exploit has been made public, leaving affected systems potentially vulnerable until a patch is released. Despite early disclosure to the vendor, they have yet to respond or provide a fix.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.