Cross Site Scripting Vulnerability in Anchor CMS
CVE-2024-37732
6.1MEDIUM
What is CVE-2024-37732?
A critical Cross Site Scripting (XSS) vulnerability has been identified in Anchor CMS version 0.12.7, which allows attackers to exploit the system by executing arbitrary code. This vulnerability is triggered when a specially crafted .pdf file is processed by the CMS, potentially leading to unauthorized actions within the application. Maintaining robust security practices and ensuring timely updates can help mitigate risks associated with such vulnerabilities.
References
EPSS Score
16% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
