CVE-2024-3542
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Apr 10, 2024
Updated: Jun 26, 2024
CWE ID 22
Summary
CVE-2024-3542 is a newly disclosed vulnerability affecting the Campcodes Church Management System version 1.0. The issue lies within the /admin/add_visitor.php file and involves a cross-site scripting (XSS) vulnerability. The manipulation of the mobile argument can be exploited remotely to inject malicious scripts, potentially leading to unauthorized access or data theft. This vulnerability, identified as VDB-259912, has been made public, increasing the risk of exploitation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share