CVE-2024-24468
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Feb 5, 2024
Updated: Feb 7, 2024
CWE ID 352
Summary
CVE-2024-24468 is a Cross-Site Request Forgery (CSRF) vulnerability discovered in flusity-CMS version 2.33. A remote attacker can exploit this weakness in the add_customblock.php file, resulting in the execution of arbitrary code. This issue poses a significant risk as an attacker can manipulate the victim's web session to perform unintended actions, potentially leading to data theft or website defacement. It is crucial that users of flusity-CMS update to the latest version to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share