CVE-2024-3081

CVSS 2.0 Score 4.0 of 10 (medium)

Details

Published Mar 29, 2024
Updated: May 17, 2024
CWE ID 79

Summary

CVE-2024-3081 is a newly identified vulnerability affecting EasyCorp EasyAdmin versions up to 4.8.9. This issue lies in the Autocomplete component's autocomplete.js file (assets/js/autocomplete.js) and its function Autocomplete. An attacker can exploit this Cross-Site Scripting (XSS) vulnerability by manipulating the item argument, enabling them to inject malicious scripts remotely. To mitigate this risk, users are advised to upgrade to EasyAdmin version 4.8.10, which includes the patch with identifier 127436e4c3f56276d548070f99e61b7234200a11. The Common Vulnerabilities and Exposures (CVE) database has assigned the identifier VDB-258613 to this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share