CVE-2024-51785
CVSS 3.1 Score 4.4 of 10 (medium)
Details
Published Nov 9, 2024
Updated: Nov 12, 2024
CWE ID 918
Summary
CVE-2024-51785 is a Server-Side Request Forgery (SSRF) vulnerability affecting I Thirteen Web Solution's Responsive Filterable Portfolio, from version n/a through 1.0.22. An attacker can exploit this flaw to send malicious HTTP requests to the server, potentially leading to unauthorized data access or execution of server-side code. The impact of this vulnerability could include information disclosure and server compromise. It's crucial for users to update their portfolio plugin to a patched version as soon as possible to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.