JavaScript Injection Vulnerability in rAthena FluxCP Web Control Panel
CVE-2024-45799
What is CVE-2024-45799?
The FluxCP web-based Control Panel for rAthena servers, written in PHP, is exposed to a JavaScript injection vulnerability. This flaw exists due to insufficient sanitization of the vendor and buyer list pages, as well as shop names. Consequently, attackers can exploit this vulnerability by injecting arbitrary JavaScript code that gets executed in the browsers of users visiting the affected shop pages. This could lead to the theft of session information from logged-in users, compromising their accounts. It is imperative for all users to upgrade to version 1.3 or later, as no workarounds are available to mitigate this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
