CVE-2024-12793

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Dec 19, 2024
Updated: Jan 6, 2025
CWE ID 22

Summary

CVE-2024-12793 is a newly disclosed vulnerability affecting PbootCMS versions up to 5.2.3. The issue lies within the file apps/home/controller/IndexController.php and stems from a path traversal vulnerability. By manipulating the argument tag, an attacker can gain unauthorized access to sensitive files and directories. This vulnerability can be exploited remotely, posing a significant risk. The exploit has become publicly available, increasing the urgency for affected organizations to upgrade to version 5.2.4 to mitigate the risk. It is strongly advised to update the affected component as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share