CVE-2024-40347
Hyland
CVE-2024-40347 is a reflected cross-site scripting (XSS) vulnerability found in Hyland Alfresco Platform 23.2.1-r96. This flaw allows attackers to inject malicious code into a user's browser by crafting a specific payload within the 'htmlid' parameter. An attacker could exploit this by tricking a user into clicking a malicious link. While the CVSS score is 6.1, the SOCRadar Vulnerability Risk Score (SVRS) is 38 indicating moderate risk, despite being tagged as In The Wild. This suggests that while exploitation is possible, active exploitation is not widespread. Successful exploitation allows the attacker to execute arbitrary code within the user's browser, potentially leading to session hijacking or data theft. Organizations using the affected Alfresco Platform version should investigate and apply the appropriate patches to mitigate this risk, especially in light of potential for malicious code execution.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.