Redis Desktop Manager vulnerable to Cross Site Scripting (XSS)
CVE-2024-23998
9.6CRITICAL
Summary
A Cross-Site Scripting (XSS) vulnerability has been identified in GoAnother Redis Desktop Manager versions up to and including 1.6.1. The flaw resides in the Setting.vue component, allowing attackers to inject malicious scripts. Such an attack could lead to the execution of unauthorized scripts in the context of the user's session, potentially compromising sensitive user data and enabling further attacks across the application. Users of affected versions should take immediate action to mitigate risks associated with this vulnerability.
References
EPSS Score
8% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved