CVE-2024-29117
CVE-2024-29117: Stored Cross-Site Scripting (XSS) vulnerability in Cimatti Consulting Contact Forms. This flaw allows attackers to inject malicious scripts into web pages via the contact form, affecting versions up to 1.7.0. Although the CVSS score is 0, indicating a seemingly low immediate impact, the SOCRadar Vulnerability Risk Score (SVRS) is 30, suggesting some level of threat activity. Successful exploitation could lead to data theft, session hijacking, or defacement of the website, even though the SVRS score isn't critical. Because this vulnerability permits attackers to inject malicious code directly into the website's database via user input, anyone visiting the contact form could be exposed. Cimatti Consulting should release a patch or provide mitigation steps to address this vulnerability quickly. Although not critical currently, XSS vulnerabilities can pose a significant risk to user data and website integrity if exploited.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.