NVD disclosure day

Published threat advisories for August 29, 2024

CVE advisoryKnown Exploit

CVE-2024-6670

WhatsUp Gold Password Retrieval Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability in WhatsUp Gold allows attackers to retrieve encrypted user passwords. This impacts organizations by potentially exposing user credentials and enabling further unauthorized access. The business risk involves compromised data and system security.

• CISA KEV

CVE advisoryCRITICAL

CVE-2024-44778

vTiger CRM 7.4.0 Reflected Cross-Site Scripting Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A reflected cross-site scripting vulnerability in vTiger CRM could allow an attacker to execute arbitrary code in a user's browser. This is achieved by tricking a user into visiting a crafted link that exploits a flaw in the index page's 'parent' parameter. This could potentially compromise a user's browser context and

CVE advisoryCRITICAL

CVE-2024-44777

vTiger CRM Tag Reflected Cross-Site Scripting Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A reflected cross-site scripting vulnerability in vTiger CRM allows attackers to execute arbitrary code in a user's browser by injecting a crafted payload into the tag parameter of the index page. This could impact user sessions and data accessible through their browser. Confirm the presence and reachability of vTiger