CVE-2024-12894
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2024-12894 is a newly identified critical vulnerability affecting TreasureHuntGame's TreasureHunt up to version 963e0e0. This issue lies in an unknown function of the file "acesso.php," which can be exploited through sql injection by manipulating the "usuario" argument. The vulnerability is remotely exploitable. Since TreasureHunt uses a rolling release for continuous delivery, no specific version details for the affected or updated releases have been disclosed. To mitigate this risk, it is advisable to apply the patch with the identifier 8bcc649abc35b7734951be084bb522a532faac4e as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.