CVE-2024-4735

CVSS 2.0 Score 4.0 of 10 (medium)

Details

Published May 14, 2024
Updated: Jun 4, 2024
CWE ID 79

Summary

CVE-2024-4735 is a recently disclosed vulnerability affecting the Campcodes Legal Case Management System 1.0. The issue lies within an unidentified functionality of the /admin/tasks file, which can be exploited through manipulation of the task_subject argument. This leads to Cross-Site Scripting (XSS), allowing attackers to inject malicious code into a user's browser. The vulnerability can be exploited remotely, and the exploit has been made public, increasing the risk to affected systems. The Vulnerability Database has assigned the identifier VDB-263821 to this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share