CVE-2024-10927

CVSS 2.0 Score 4.0 of 10 (medium)

Details

Published Nov 6, 2024
CWE ID 79
CWE ID 74

Summary

CVE-2024-10927 is a newly disclosed vulnerability affecting MonoCMS up to version 20240528. This issue, located in the Account Information Page's /monofiles/account.php file, is classified as problematic. The vulnerability stems from a flaw in an unknown function, where manipulation of the userid argument results in cross-site scripting (XSS). Attacks can be executed remotely, increasing the risk for exploitation. Unfortunately, the exploit has been made public, leaving affected systems potentially vulnerable until a patch is released. Despite early disclosure to the vendor, they have yet to respond or provide a fix.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share