CVE-2024-10999
CVSS 3.1 Score 7.2 of 10 (high)
Details
Published Nov 8, 2024
Updated: Nov 13, 2024
CWE ID 434
CWE ID 284
Summary
CVE-2024-10999 is a recently disclosed vulnerability affecting the CodeAstro Real Estate Management System version 1.0. This issue lies within an unknown function of the About Us Page's /aboutadd.php file. The vulnerability allows for unrestricted uploads by manipulating the aimage argument. The attack can be executed remotely, increasing the risk to affected systems. Public disclosure of the exploit heightens the potential for malicious actors to exploit this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.