CVE-2024-41475
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Aug 12, 2024
Updated: Sep 18, 2024
CWE ID 346
Summary
CVE-2024-41475 is a newly disclosed vulnerability affecting Gnuboard g6 version 6.0.7. This issue arises due to a Cross-Origin Resource Sharing (CORS) misconfiguration, allowing unauthorized access to user sessions. An attacker can hijack a user's session by making malicious requests from another domain, potentially leading to sensitive data exposure or unauthorized actions within the application. It is crucial that users update their Gnuboard g6 installation to a patched version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- SIR