CVE-2024-29879
Sapplica
CVE-2024-29879: Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2. This allows attackers to inject malicious scripts into web pages viewed by users. The vulnerability exists in the 'business_id' parameter of the /sentrifugo/index.php/index/getdepartments/format/html endpoint. An attacker can exploit this vulnerability by crafting a malicious URL and tricking a user into clicking it. Successful exploitation could lead to session data theft, potentially compromising user accounts. Despite a CVSS score of 6.1, the SOCRadar Vulnerability Risk Score (SVRS) is 30, indicating a lower immediate risk compared to vulnerabilities with SVRS scores above 80. However, given the presence of CWE-79, which is a common attack vector, diligent patching and user awareness are recommended to mitigate potential threats.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.