CVE-2024-12895
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Dec 22, 2024
Updated: Jan 10, 2025
CWE ID 74
CWE ID 89
Summary
CVE-2024-12895 is a critical vulnerability affecting TreasureHuntGame's TreasureHunt up to version 963e0e0. The issue lies within the console_log function of the checkflag.php file, which is susceptible to SQL injection. Manipulation of the problema argument enables remote attackers to exploit this vulnerability. A patch with the identifier 8bcc649abc35b7734951be084bb522a532faac4e is available to mitigate this risk. It is strongly advised to apply the patch promptly to prevent potential exploitation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.