CVSS 3.1 Score 9.8 of 10 (high)


Published Jan 19, 2024
Updated: Mar 21, 2024
CWE ID 610


CVE-2024-0728 is a critical vulnerability found in ForU CMS up to 2020-06-23. It affects an unknown functionality of the file channel.php and allows for remote file inclusion through the manipulation of the argument c_cmodel. The exploit has been publicly disclosed and may be used by attackers. The vulnerability has a high impact on confidentiality and integrity, with a CVSS score of 9.8. No privileges are required for exploitation, and there is no user interaction needed. The affected product is usBONV, and the potential danger it poses to organizations is significant, as it allows unauthorized access to sensitive files. Remediation measures should be taken immediately to patch or update the affected CMS version to mitigate this vulnerability.

Explore Beyond the CVE Basics with Recorded Future's Vulnerability Intelligence

Note: This is just a basic overview providing quick insights into CVE-2024-0728 information. Gain full access to comprehensive CVE data, risk scores, prioritization, and mitigation data through Recorded Future's Vulnerability Intelligence:
  • Prioritize with Risk-Based Scoring
  • Explore the Extensive Vulnerability Database
  • Receive Early Alerts on Emerging CVEs
  • Focus on Critical Exploitable Vulnerabilities
  • Streamline Remediation with Integration Options