CVE-2024-1304
MEDIUM 6.3EPSS 0.7%
Cross-site scripting vulnerability in Badger Meter Monitool that affects versions up to 4.6.3 and earlier. This vulnerability allows a remote attacker to send a specially crafted javascript payload to an authenticated user and partially hijack their browser session.
- CVSS v3.1
- 6.1 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - CVSS v3.1
- 6.3 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L - EPSS
- 0.67% chance of exploitation in the next 30 days, 49th percentile
- Published
- 2024-03-12
- Updated
- 2024-08-22
Proof-of-concept exploits (1)
- guillermogm4/CVE-2024-1304---Badgermeter-moni-tool-Reflected-Cross-Site-Scripting-XSS0★ · 2024-02-08