CVE-2024-9276

CVSS 2.0 Score 4 of 10 (medium)

Details

Published Sep 27, 2024
Updated: Sep 30, 2024
CWE ID 79

Summary

CVE-2024-9276 is a newly disclosed vulnerability affecting TMsoft MyAuth Gateway version 3. The issue lies in an unknown function of the /index.php file, which can be exploited through manipulation of the console/nocache/cmd argument. This vulnerability results in cross-site scripting, allowing remote attackers to inject malicious code into a user's web browser. The exploit for this vulnerability has been made public, increasing the risk of widespread attacks. Despite early disclosure to the vendor, they have not responded or issued a patch.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share