CVE-2024-32789
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2024-32789 is a serious vulnerability affecting Seers, where a Cross-Site Request Forgery (CSRF) weakness combines with Cross-Site Scripting (XSS). Seers versions from n/a to 8.1.0 are susceptible to this issue. An attacker exploiting this flaw can inject malicious scripts into users' browsers and gain unauthorized access to their accounts or perform actions on their behalf. The CSRF component allows the attacker to bypass same-origin policy restrictions, while the XSS vulnerability delivers the payload to the victim's browser. This combination creates a significant risk and requires immediate remediation for affected Seers installations.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.