CVE-2024-44807

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Oct 11, 2024
Updated: Oct 15, 2024
CWE ID 552

Summary

CVE-2024-44807 is a directory listing vulnerability affecting the baserCMS plugin in D-ZERO CO., LTD. BurgerEditor and BurgerEditor Limited Edition versions prior to 2.25.1. This issue permits remote attackers to access a list of uploaded files, potentially exposing sensitive information. The vulnerability exists due to insufficient access controls, enabling unauthorized individuals to explore the file structure of affected systems. This information disclosure could lead to further exploitation and potential data breaches. System administrators are advised to update to the latest version of the plugin to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share