CVE-2024-0728
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2024-0728 is a critical vulnerability found in ForU CMS up to 2020-06-23. It affects an unknown functionality of the file channel.php and allows for remote file inclusion through the manipulation of the argument c_cmodel. The exploit has been publicly disclosed and may be used by attackers. The vulnerability has a high impact on confidentiality and integrity, with a CVSS score of 9.8. No privileges are required for exploitation, and there is no user interaction needed. The affected product is usBONV, and the potential danger it poses to organizations is significant, as it allows unauthorized access to sensitive files. Remediation measures should be taken immediately to patch or update the affected CMS version to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Advisories, Assessments, and Mitigations
Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future
- Gain complete coverage of your cyber, third party, and physical attack surface
- Proactively mitigate threats before they turn into costly attacks
- Make fast, effective, data-driven decisions