CVE-2024-42007

CVSS 3.1 Score 5.8 of 10 (medium)

Details

Published Jul 26, 2024
Updated: Aug 1, 2024
CWE ID 22
CWE ID 548

Summary

CVE-2024-42007 is a newly identified vulnerability affecting SPX (php-spx) versions up to 0.4.15. This issue enables an attacker to perform Directory Traversal attacks on SPX_UI_URI, allowing them to read arbitrary files on the targeted system. Successful exploitation could lead to the disclosure of sensitive information, potentially resulting in significant privacy concerns or unauthorized system access. Organizations using the affected software are urged to update to a patched version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share