CVE-2024-2593
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2024-2593 is a Cross-Site Scripting (XSS) vulnerability affecting AMSS++ version 4.31. The issue lies in the insufficient encoding of user-controlled input, specifically in the 'b_id' parameter of the /amssplus/modules/book/main/bookdetail_group.php file. An attacker can exploit this flaw by sending a malicious URL to an authenticated user, potentially stealing their session cookie credentials. This vulnerability poses a significant risk and requires immediate attention from users and administrators alike. It is recommended that affected systems be updated to the latest version of AMSS++ to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.