CVE-2024-45186

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Oct 2, 2024
Updated: Oct 4, 2024
CWE ID 94

Summary

CVE-2024-45186 is a newly identified vulnerability affecting FileSender before version 2.49. This issue permits server-side template injection (SSTI), enabling an attacker to gain unauthorized access to sensitive data, specifically credentials, by manipulating templates used by the FileSender software. The vulnerability poses a significant risk as it allows attackers to bypass authentication mechanisms and gain privileged access to the system. Successful exploitation could lead to data theft or system compromise. Users are encouraged to upgrade to the latest version of FileSender to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share