CVE-2024-10928
CVSS 2.0 Score 4.0 of 10 (medium)
Details
Published Nov 6, 2024
CWE ID 79
CWE ID 74
Summary
CVE-2024-10928 is a newly disclosed vulnerability affecting MonoCMS up to version 20240528. This issue lies in the Posts Page component's opensaved.php file, where the filtcategory/filtstatus argument is manipulable. This manipulation results in a cross-site scripting (XSS) vulnerability, allowing remote attackers to inject malicious code into users' browsers. The vendor has been contacted regarding this disclosure but has not responded, leaving users at risk until a patch is released.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share