CVSS 3.1 Score 9.8 of 10 (high)


Published May 14, 2024
CWE ID 434


CVE-2024-4825 is a vulnerability found in Agentejo Cockpit CMS v0.5.5, which allows for arbitrary file uploads through the '/media/api' parameter via a post request. This vulnerability poses a significant danger to organizations as it enables attackers to upload files to the server and compromise the entire infrastructure. The base severity of this vulnerability is rated as CRITICAL with a base score of 9.8, indicating its high impact on integrity and confidentiality. The exploitability score is 3.9, signifying a moderate level of difficulty for potential attackers. It is crucial for affected organizations to remediate this vulnerability promptly to mitigate potential risks and protect their systems and data.


Explore Beyond the CVE Basics with Recorded Future's Vulnerability Intelligence

Note: This is just a basic overview providing quick insights into CVE-2024-4825 information. Gain full access to comprehensive CVE data, risk scores, prioritization, and mitigation data through Recorded Future's Vulnerability Intelligence:
  • Prioritize with Risk-Based Scoring
  • Explore the Extensive Vulnerability Database
  • Receive Early Alerts on Emerging CVEs
  • Focus on Critical Exploitable Vulnerabilities
  • Streamline Remediation with Integration Options