CVE-2024-12901
CVSS 2.0 Score 5 of 10 (medium)
Details
Published Dec 23, 2024
CWE ID 285
CWE ID 266
Summary
CVE-2024-12901 is a critical vulnerability affecting FoxCMS versions up to 1.2. This issue lies within the unknown functionality of the /app/api/controller/Site.php file in the API Endpoint component. Manipulation of the password argument results in unauthorized access, making the attack remotely exploitable. The exploit for this vulnerability has already been disclosed to the public, increasing the risk of potential attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.