CVE-2024-11125

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Nov 12, 2024
Updated: Nov 15, 2024
CWE ID 352
CWE ID 862

Summary

CVE-2024-11125 is a recently disclosed vulnerability affecting GetSimpleCMS version 3.3.16. The issue lies in the processing of the /admin/profile.php file, which can result in a cross-site request forgery (CSRF) vulnerability. An attacker can exploit this flaw remotely, potentially gaining unauthorized access to user accounts. Although the vulnerability was reported to the vendor, they have yet to respond or provide a patch. As a result, the exploit is publicly available and poses an immediate threat to users running the affected version of GetSimpleCMS.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share