CVE-2024-40487
CVSS 3.1 Score 7.6 of 10 (high)
Details
Summary
CVE-2024-40487 is a newly discovered stored Cross-Site Scripting (XSS) vulnerability. This issue affects the "/view_type.php" file in the Kashipara Live Membership System v1.0. Attackers can exploit this vulnerability by injecting malicious code into the membershipType parameter. Successful exploitation allows remote attackers to execute arbitrary code on affected systems, potentially leading to serious security breaches. This vulnerability poses a significant risk to websites using the affected version of Kashipara Live Membership System and underscores the importance of timely software updates and secure coding practices.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.