CVE-2024-47227
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2024-47227 is a cross-site scripting (XSS) vulnerability found in iRedAdmin versions prior to 2.6, affecting several products including y1eQY9 and y1eQY8. The vulnerability allows attackers to inject malicious scripts via the order_name parameter, posing a medium severity risk with a CVSS base score of 6.1. Remediation involves upgrading to iRedAdmin version 2.6 or later, as indicated in the vendor's advisory and patch notes available on their GitHub repository. The exploitation of this vulnerability requires user interaction and is considered to have low integrity and confidentiality impacts but can lead to potential security breaches if leveraged effectively by attackers. Organizations using affected versions should prioritize updates to mitigate associated risks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.