CVE-2024-12990

CVSS 2.0 Score 4 of 10 (medium)

Details

Published Dec 27, 2024
CWE ID 601

Summary

CVE-2024-12990 is a newly disclosed vulnerability affecting the ruifang-tech Rebuild 3.8.6 Admin Verification Page component. This issue, classified as problematic, impacts the /user/admin-verify file. An attacker can exploit this vulnerability by manipulating the nexturl argument with the input http://localhost/evil.html, resulting in an open redirect. This vulnerability allows remote attacks, meaning an attacker does not need to have local access to exploit it. The exploit has been made public, increasing the risk of potential attacks. Despite early disclosure to the vendor, they have not responded or taken any action to address the issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share