CVE-2024-6415
CVE-2024-6415 exposes Ingenico Estate Manager to cross-site scripting (XSS) attacks. This vulnerability allows remote attackers to inject malicious scripts into the /emgui/rest/preferences/PREF_HOME_PAGE/sponsor/3/ endpoint through the URL parameter. The New Widget Handler component is affected, potentially compromising user sessions and data. Despite the low CVSS score of 2.4, CVE-2024-6415 is publicly disclosed, indicating a higher risk of exploitation. While the SVRS score is 38, reflecting a moderate risk, the fact that the vendor is unresponsive amplifies concerns. Immediate patching is advisable to mitigate the potential for malicious script injection and account compromise, especially given that the exploit is already in the wild.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.