CVE-2024-1704
CVSS 3.1 Score 8.1 of 10 (high)
Details
Published Feb 21, 2024
Updated: Jan 3, 2025
CWE ID 22
Summary
CVE-2024-1704 is a newly disclosed critical vulnerability affecting ZhongBangKeJi CRMEB 5.2.2. The issue lies within the save/delete function of the file /adminapi/system/crud, which can be manipulated to engage in path traversal. This exploit has become public, increasing the risk of potential attacks. The vulnerability identifier is VDB-254392, and despite early notification to the vendor, they have not responded to the disclosure.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share