CVE-2024-47051
CVSS 3.1 Score 9.1 of 10 (high)
Details
Summary
CVE-2024-47051: Mautic versions before 5.2.3 contain two critical vulnerabilities that can be exploited by authenticated users. The first issue is a Remote Code Execution (RCE) vulnerability in the asset upload functionality. Insufficient file extension checks allow attackers to bypass restrictions and upload executable files, such as PHP scripts. The second vulnerability is a Path Traversal File Deletion issue in the upload validation process. By manipulating the file deletion process, authenticated users can delete arbitrary files on the host system. These vulnerabilities pose a significant risk and require immediate attention and patching.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- CORE
Affected Vendors
- JET Charge Pty Ltd