CVE-2024-50714

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Dec 27, 2024
Updated: Dec 28, 2024
CWE ID 918

Summary

CVE-2024-50714 is a newly disclosed Server-Side Request Forgery (SSRF) vulnerability affecting the Smart Agent v.1.1.0 of smarts-srl.com. An attacker can exploit this issue by crafting a malicious script and sending it to the /FB/getFbVideoSource.php component. Successful exploitation allows the attacker to obtain sensitive information from the affected server, potentially leading to serious security consequences. The vulnerability poses a significant risk to organizations using the impacted version of smarts-srl.com Smart Agent and urges immediate patching or mitigation measures.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share