CVE-2024-51902

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Nov 19, 2024
CWE ID 79

Summary

CVE-2024-51902 is a Cross-site Scripting (XSS) vulnerability affecting the Oliver Schaal TinyCode software, from an unknown version up to and including 1.2.1. The issue arises due to improper neutralization of user inputs during web page generation. An attacker can exploit this flaw to inject malicious scripts into a web page, enabling unauthorized access or data theft when the page is accessed by other users. This vulnerability poses a significant risk to organizations and individuals using the affected software, highlighting the importance of keeping software up to date with the latest security patches.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share