CVE-2024-51908
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2024-51908 is a Cross-site Scripting (XSS) vulnerability affecting the Gonzalo Geraldo Adventure Bucket List application from versions n/a through 1.0.9. The flaw stems from improper neutralization of user inputs during web page generation, creating a DOM-Based XSS risk. Attackers can exploit this issue by injecting malicious scripts into affected web pages. Successful attacks could lead to information disclosure, unauthorized actions, or user redirection, putting users at risk. It is crucial for users to update their applications to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.