CVE-2024-26481
CVE-2024-26481: Reflected XSS vulnerability in Kirby CMS v4.1.0. This flaw allows an attacker to inject malicious scripts into a user's browser session through a crafted URL parameter, potentially leading to unauthorized actions. Despite a CVSS score of 0, indicating a base severity of none, the SVRS of 30 suggests a low-risk vulnerability. While not immediately critical, this self-XSS issue could be exploited if combined with social engineering tactics to trick users into executing the malicious URL. Users should still apply mitigations to prevent potential exploitation, particularly if the CMS is used in an environment with sensitive data. Ignoring this vulnerability could lead to account compromise or data theft if an attacker can successfully trick a user. Although it’s tagged "In the Wild," the low SVRS score suggests it's not widely exploited.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.