CVE-2024-12700
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Dec 19, 2024
CWE ID 434
Summary
CVE-2024-12700 represents a significant vulnerability in which authenticated, low-privileged users can exploit an unrestricted file upload feature. By uploading a malicious JSP shell, these users can gain the privileges of the web server and execute arbitrary code. This vulnerability poses a serious threat to security, as it allows unauthorized access and potential data breaches. Organizations using affected systems are advised to apply patches or implement workarounds as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.