CVE-2024-5415
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published May 28, 2024
CWE ID 79
Summary
CVE-2024-5415 is a newly discovered vulnerability in PhpMyBackupPro version 2.3. This issue allows an attacker to carry out Cross-Site Scripting (XSS) attacks through the backup.php, 'comments' and 'db' parameters. By creating a maliciously crafted URL, an attacker can potentially steal session details from unsuspecting victims. This security flaw poses a serious threat and requires immediate attention from PhpMyBackupPro users to update to a patched version.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share