CVE-2024-1750
CVSS 3.1 Score 8.1 of 10 (high)
Details
Published Feb 22, 2024
Updated: Dec 31, 2024
CWE ID 502
Summary
CVE-2024-1750 is a critical vulnerability affecting TemmokuMVC up to version 2.3. The issue lies in the function get_img_url/img_replace within the Image Download Handler component's lib/images_get_down.php library. This vulnerability results in deserialization, allowing for remote attacks. The attack complexity is higher, and the exploitability is reportedly difficult, but an exploit has been made public. The identifier for this vulnerability is VDB-254532. Unfortunately, despite early disclosure, the vendor has not responded.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.