CVE-2024-24506
CVE-2024-24506 is a Cross Site Scripting (XSS) vulnerability affecting Lime Survey Community Edition v.5.3.32+220817. This vulnerability allows remote attackers to inject and execute arbitrary code through the Administrator email address parameter within the General Setting function. Although the CVSS score is 0, indicating minimal immediate impact, the "In The Wild" tag and active exploit publication elevates the risk. With an SOCRadar Vulnerability Risk Score (SVRS) of 30, the threat is considered moderate, requiring monitoring and eventual patching. Exploitation could lead to account compromise and unauthorized access. Organizations using Lime Survey should prioritize applying the latest patches or mitigations to prevent potential cyberattacks.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.