CVE-2024-46446

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Oct 7, 2024
Updated: Oct 11, 2024
CWE ID 22

Summary

CVE-2024-46446 is a newly disclosed vulnerability affecting Mecha CMS version 3.0.0. Hackers can exploit this Directory Traversal issue by crafting malicious cookies and URIs that circumvent user authentication. Consequently, they can manipulate parameters and execute unauthorized POST requests, leading to the deletion of arbitrary files or a complete website takeover. This vulnerability poses a severe threat to websites using the affected CMS and necessitates immediate patching.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share