First published: Tue Aug 20 2024(Updated: )
Priority - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
Credit: cna@cyber.gov.il
Affected Software | Affected Version | How to fix |
---|---|---|
Priority Software Priority | <24.0 |
Upgrade to version 24.0 or later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-41697 is classified as a medium severity vulnerability due to its potential impact through cross-site scripting (XSS).
To fix CVE-2024-41697, ensure that user inputs are properly validated and sanitized to prevent injection of malicious scripts.
CVE-2024-41697 affects all versions of Priority software up to 24.0, inclusive.
CVE-2024-41697 is an XSS vulnerability caused by improper neutralization of script-related HTML tags in web pages.
By exploiting CVE-2024-41697, attackers can execute arbitrary JavaScript in the context of a user's browser, potentially leading to session hijacking or data theft.