CVE-2024-11210

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Nov 14, 2024
Updated: Nov 15, 2024
CWE ID 22

Summary

CVE-2024-11210 is a critical vulnerability affecting EyouCMS 1.51. The issue lies in the function editFile of the FilemanagerLogic.php file. Attackers can manipulate the activepath argument to conduct path traversal, potentially gaining unauthorized access to sensitive data or executing malicious code. The exploit has been made public, increasing the risk of remote attacks. Despite early notification to the vendor, they have not responded.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share