CVE-2024-33102
CVE-2024-33102: Cross-site Scripting (XSS) vulnerability in ThinkSAAS v3.7.0. Discover a security flaw within ThinkSAAS v3.7.0, specifically in the /pubs/counter.php component, where a stored XSS vulnerability allows attackers to inject malicious scripts. This vulnerability enables the execution of arbitrary web scripts or HTML by injecting a crafted payload into the 'code' parameter. The CWE-79 classified vulnerability could be exploited by attackers to compromise user sessions or deface the web application. While the CVSS score is 0, meaning there is no impact according to CVSS, the SOCRadar Vulnerability Risk Score (SVRS) is 30, indicating a low risk but not negligible. The presence of the 'In The Wild' tag signals that the exploit is already being actively used, necessitating caution and potential mitigation actions despite the relatively low SVRS score. Organizations using ThinkSAAS v3.7.0 should patch or mitigate the vulnerability promptly to prevent potential exploitation.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.