CVE-2024-10089
CVE-2024-10089 exposes SoftCOM iKSORIS's Internet Starter module to a Stored XSS vulnerability. Attackers can inject malicious scripts into user data forms, executing them within the user's browser context. This vulnerability, categorized as CWE-79, has been addressed in version 79.0. Despite the low CVSS score of 0, CVE-2024-10089 should be taken seriously because malicious scripts can steal cookies, create fake requests, and redirect users to malicious websites. The SOCRadar Vulnerability Risk Score (SVRS) is 34, suggesting a moderate risk, although the "In The Wild" tag indicates that exploits have been observed, necessitating vigilance and prompt patching. This vulnerability could lead to significant data breaches and unauthorized account access if exploited. The potential for widespread impact on users underscores the importance of upgrading to the patched version immediately.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.