CVE-2024-9414 - CVE House
Back to Database
Status published High CVE-2024-9414

Cross-site Scripting vulnerability in LCDS LAquis SCADA

Vulnerability Description

In LAquis SCADA version 4.7.1.511, a cross-site scripting vulnerability could allow an attacker to inject arbitrary code into a web page. This could allow an attacker to steal cookies, redirect users, or perform unauthorized actions.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-9414

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Mounir Aarab reported this vulnerability to CISA.

More from LCDS - Leão Consultoria e Desenvolvimento de Sistemas Ltda ME

View All →

Affected Vendor

LCDS - Leão Consultoria e Desenvolvimento de Sistemas Ltda ME

View all reports →

Affected Software

LAquis SCADA
Vulnerable Versions:
4.7.1.511

Timeline

Official Publish: October 17th, 2024
Last Modified: October 17th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)