CVE-2024-47051

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Feb 26, 2025
CWE ID 94
CWE ID 23

Summary

CVE-2024-47051: Mautic versions before 5.2.3 contain two critical vulnerabilities that can be exploited by authenticated users. The first issue is a Remote Code Execution (RCE) vulnerability in the asset upload functionality. Insufficient file extension checks allow attackers to bypass restrictions and upload executable files, such as PHP scripts. The second vulnerability is a Path Traversal File Deletion issue in the upload validation process. By manipulating the file deletion process, authenticated users can delete arbitrary files on the host system. These vulnerabilities pose a significant risk and require immediate attention and patching.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share