CVE-2024-13198
CVSS 2.0 Score 2.6 of 10 (low)
Details
Published Jan 9, 2025
CWE ID 203
CWE ID 204
Summary
CVE-2024-13198 is a recently disclosed vulnerability affecting the langhsu Mblog Blog System 3.5.0. This issue lies within an unidentified function in the /login file, leading to noticeable discrepancies in response. The attack can be launched remotely, making it a potential threat to security. The complexity of an exploit is reportedly high, with difficulty in execution. Unfortunately, the exploit has been made public, increasing the risk of potential attacks. Despite early notification, the vendor has not responded to the disclosure.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Mblog Blog System