CVE-2024-29644
CVE-2024-29644 is a Cross Site Scripting (XSS) vulnerability found in dcat-admin version 2.1.3 and earlier. This security flaw allows a remote attacker to inject malicious scripts into the user login box, potentially leading to arbitrary code execution within a user's browser session. With a CVSS score of 6.1 and an SVRS of 30, the immediate risk is moderate. However, exploitation could lead to session hijacking, defacement, or the theft of sensitive user data. While the CVSS score indicates a medium severity, businesses using dcat-admin should still address this vulnerability to prevent potential security breaches. The vulnerability highlights the importance of input sanitization and secure coding practices to mitigate XSS attacks. Prompt patching or mitigation is advised to protect against potential exploitation.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.