Arbitrary Code Execution via Cross-Site Scripting (XSS) in dcat-admin
CVE-2024-29644
6.1MEDIUM
What is CVE-2024-29644?
A Cross Site Scripting vulnerability exists in Dcat-Admin, which is a web application framework. This flaw allows a remote attacker to inject malicious scripts through the user login box, potentially leading to unauthorized execution of arbitrary code. Attackers exploiting this vulnerability could compromise user accounts and perform unauthorized actions on behalf of legitimate users, making it critical for organizations using this product to implement necessary security measures and updates.
