CVE-2024-10927

CVSS 2.0 Score 4 of 10 (medium)

Details

Published Nov 6, 2024
Updated: Nov 8, 2024
CWE ID 79
CWE ID 74

Summary

CVE-2024-10927 is a newly disclosed vulnerability affecting MonoCMS up to version 20240528. This issue, classified as problematic, impacts an unidentified function within the /monofiles/account.php component of the Account Information Page. The vulnerability grants an attacker the ability to execute cross-site scripting (XSS) attacks by manipulating the userid argument. These assaults can be carried out remotely, and the exploit code has been made public. Despite being informed of the disclosure, the vendor has failed to respond or issue a patch.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share