CVE-2024-6941

CVSS 2.0 Score 4.0 of 10 (medium)

Details

Published Jul 21, 2024
Updated: Jul 22, 2024
CWE ID 79

Summary

CVE-2024-6941 is a newly disclosed vulnerability affecting ThinkSAAS 3.7.0. This issue is classified as problematic, allowing for cross-site scripting (XSS) attacks. The vulnerability is located in the file app/system/action/do.php and is triggered by manipulating the arguments site_title, site_subtitle, site_key, site_desc, site_url, site_email, and site_icp. These manipulations can lead to XSS injection, potentially enabling remote attackers to execute malicious scripts in users' browsers. The exploit for this vulnerability has been made public, increasing the risk of exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share