CVE-2024-4304
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Apr 29, 2024
CWE ID 754
Summary
CVE-2024-4304 is a newly discovered Cross-Site Scripting (XSS) vulnerability affecting GT3 Soluciones SWAL. The issue lies in the Titular parameter of the 'Gestion Documental > Seguimiento de Expedientes > Alta de Expedientes' feature. A successful exploit of this reflected XSS vulnerability could allow an attacker to inject and execute malicious code in a user's web browser. This could lead to unauthorized access to sensitive information, or even session hijacking. Users are strongly advised to update their systems as soon as a patch becomes available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share