CVE-2024-25415

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Feb 16, 2024
Updated: Jan 13, 2025
CWE ID 94

Summary

CVE-2024-25415 is a newly disclosed remote code execution (RCE) vulnerability. It affects the /admin/define_language.php file in CE Phoenix version 1.0.8.20. Attackers can exploit this vulnerability by injecting a carefully crafted payload into the english.php file. Successful exploitation allows the attacker to execute arbitrary PHP code, potentially leading to serious security implications. This issue poses a significant threat and underscores the importance of timely software updates.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share