CVE-2024-52370

CVSS 3.1 Score 9.9 of 10 (high)

Details

Published Nov 14, 2024
Updated: Nov 15, 2024
CWE ID 434

Summary

CVE-2024-52370 is a newly disclosed vulnerability affecting Hive Support, a WordPress Help Desk plugin. The issue permits an unauthenticated attacker to upload any file type, including malicious web shells, to the web server. This vulnerability exists in all versions of Hive Support from the unspecified version n/a up to and including 1.1.1. Successful exploitation could lead to serious security implications, such as unauthorized access, data theft, or website defacement. It is recommended that users upgrade to the latest version of the plugin as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share