CVE-2024-10571

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Nov 14, 2024
Updated: Nov 15, 2024
CWE ID 98

Summary

CVE-2024-10571 is a local file inclusion vulnerability affecting the Chartify – WordPress Chart Plugin. Versions up to and including 2.9.5 are vulnerable to this issue. The 'source' parameter can be exploited by unauthenticated attackers, enabling them to include and execute arbitrary files on the server. This can lead to bypassing access controls, obtaining sensitive data, or executing PHP code present in those files. The vulnerability poses a significant risk as it allows for the manipulation of files that are typically considered safe, such as images.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share