CVE-2024-44807
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Summary
CVE-2024-44807 is a directory listing vulnerability affecting the baserCMS plugin in D-ZERO CO., LTD. BurgerEditor and BurgerEditor Limited Edition versions prior to 2.25.1. This issue permits remote attackers to access a list of uploaded files, potentially exposing sensitive information. The vulnerability exists due to insufficient access controls, enabling unauthorized individuals to explore the file structure of affected systems. This information disclosure could lead to further exploitation and potential data breaches. System administrators are advised to update to the latest version of the plugin to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.