CVE-2024-37245
Vsourz
CVE-2024-37245: Cross-Site Scripting (XSS) vulnerability in Vsourz Digital All In One Redirection. This vulnerability allows for reflected XSS attacks, affecting versions up to 2.2.0. CVE-2024-37245 arises from improper neutralization of input during web page generation. Although the CVSS score is 6.1, indicating a medium severity, the SOCRadar Vulnerability Risk Score (SVRS) is 58, highlighting a moderate risk. Successful exploitation could allow attackers to inject malicious scripts into web pages viewed by users. This could lead to session hijacking or the theft of sensitive information. Organizations using All In One Redirection should promptly update to a patched version to mitigate potential cybersecurity risks associated with this vulnerability. Reflected XSS vulnerabilities are particularly dangerous because they can be exploited through social engineering.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.