CVE-2024-3542

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Apr 10, 2024
Updated: Jun 26, 2024
CWE ID 22

Summary

CVE-2024-3542 is a newly disclosed vulnerability affecting the Campcodes Church Management System version 1.0. The issue lies within the /admin/add_visitor.php file and involves a cross-site scripting (XSS) vulnerability. The manipulation of the mobile argument can be exploited remotely to inject malicious scripts, potentially leading to unauthorized access or data theft. This vulnerability, identified as VDB-259912, has been made public, increasing the risk of exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share