CVE-2024-22551

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Jan 26, 2024
Updated: Feb 1, 2024
CWE ID 79

Summary

CVE-2024-22551 is a newly disclosed vulnerability affecting WhatACart version 2.0.7. This issue permits an attacker to inject malicious scripts through the /site/default/search component using reflected cross-site scripting (XSS) techniques. Successful exploitation could lead to unintended execution of malicious code in a user's browser, potentially causing data theft or other unwanted actions. Users are advised to upgrade to the latest version of WhatACart to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share