CVE-2024-11215

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Nov 14, 2024
Updated: Nov 15, 2024
CWE ID 22

Summary

CVE-2024-11215 is a newly discovered vulnerability affecting version 14.1 of the EasyPHP web server. This issue is classified as an absolute path traversal vulnerability, where the server fails to restrict file access to a specific directory. An attacker can exploit this vulnerability by setting consecutive strings ' /...%5c' to bypass SecurityManager restrictions, potentially gaining unauthorized access to any file stored on the server. This could lead to sensitive data disclosure or even server takeover. It is recommended that users of EasyPHP version 14.1 upgrade to a patched version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share