CVE-2024-41640
MEDIUMCVSS 6.1/10EPSS 0.58%
Last modified
CVE-2024-41640 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. Cross Site Scripting (XSS) vulnerability in AML Surety Eco up to 3.5 allows an attacker to run arbitrary code via crafted GET request using the id parameter.. EPSS estimates a 0.58% chance of exploitation in the next 30 days.
Description
Cross Site Scripting (XSS) vulnerability in AML Surety Eco up to 3.5 allows an attacker to run arbitrary code via crafted GET request using the id parameter.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-41640?
Cross Site Scripting (XSS) vulnerability in AML Surety Eco up to 3.5 allows an attacker to run arbitrary code via crafted GET request using the id parameter.
How severe is CVE-2024-41640?
CVE-2024-41640 has a CVSS score of 6.1/10 (MEDIUM severity). The EPSS model estimates a 0.58% probability of exploitation in the next 30 days.
How do I fix CVE-2024-41640?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-41629An issue in Texas Instruments Fusion Digital Power Designer …5.5
- CVE-2024-4163The Skylab IGX IIoT Gateway allowed users to connect to it v…8
- CVE-2024-41630Stack-based buffer overflow vulnerability in Tenda AC18 V15.…7.6
- CVE-2024-41631Buffer Overflow vulnerability in host-host NEUQ_board v.1.0 …7.5
- CVE-2024-41637RaspAP before 3.1.5 allows an attacker to escalate privilege…8.3
- CVE-2024-4164A vulnerability, which was classified as critical, has been …9.8
- CVE-2024-41643An issue in Arris NVG443B 9.3.0h3d36 allows a physically pro…6.8
- CVE-2024-41644Insecure Permissions vulnerability in Open Robotics Robotic …9.8
- CVE-2024-41645Insecure Permissions vulnerability in Open Robotics Robotic …9.8
- CVE-2024-41646Insecure Permissions vulnerability in Open Robotics Robotic …9.8
- CVE-2024-41647Insecure Permissions vulnerability in Open Robotics Robotic …9.8
- CVE-2024-41648Insecure Permissions vulnerability in Open Robotics Robotic …9.8
Are you affected by CVE-2024-41640?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
