CVE-2024-0728

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jan 19, 2024
Updated: Mar 21, 2024
CWE ID 610
CWE ID 73

Summary

CVE-2024-0728 is a critical vulnerability found in ForU CMS up to 2020-06-23. It affects an unknown functionality of the file channel.php and allows for remote file inclusion through the manipulation of the argument c_cmodel. The exploit has been publicly disclosed and may be used by attackers. The vulnerability has a high impact on confidentiality and integrity, with a CVSS score of 9.8. No privileges are required for exploitation, and there is no user interaction needed. The affected product is usBONV, and the potential danger it poses to organizations is significant, as it allows unauthorized access to sensitive files. Remediation measures should be taken immediately to patch or update the affected CMS version to mitigate this vulnerability.

Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future

Note: This is just a basic overview providing quick insights into CVE-2024-0728 information. Gain full access to comprehensive CVE data, third party vulnerabilities, compromised credentials and more with Recorded Future
  • Gain complete coverage of your cyber, third party, and physical attack surface
  • Proactively mitigate threats before they turn into costly attacks
  • Make fast, effective, data-driven decisions