CVE-2024-54775
CVE-2024-54775: Cross-Site Scripting (XSS) vulnerability in Dcat-Admin versions v2.2.0-beta and v2.2.2-beta. The vulnerability is located in the /admin/auth/menu and /admin/auth/extensions components. This allows attackers to inject arbitrary web scripts into the trusted web page by exploiting this vulnerability. Despite the CVSS score of 0, indicating minimal immediate impact, the SVRS of 30 suggests a low but non-negligible risk profile. Successful exploitation could lead to session hijacking or defacement of the administrator interface. While the SVRS is relatively low, the "In The Wild" tag indicates that this vulnerability has been actively exploited, so remediation actions should be taken. This poses risks such as data theft, or unauthorized changes to the application configuration.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.