CVE-2024-45799 is a javascript injection vulnerability affecting FluxCP, a web-based control panel for rAthena servers. Attackers can inject arbitrary javascript code into vendor/buyer list pages and shop names due to a lack of sanitization. This medium-severity vulnerability (CVSS 6.1) allows for client-side execution of malicious scripts, potentially leading to session information theft from logged-in FluxCP users. There are no known workarounds, and users are advised to upgrade to version 1.3. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.3.0CPE matchmatch criteria | cpe:2.3:a:rathena:fluxcp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.