CVE-2024-52377

CVSS 3.1 Score 10.0 of 10 (high)

Details

Published Nov 14, 2024
Updated: Nov 15, 2024
CWE ID 434

Summary

CVE-2024-52377 is a newly identified vulnerability affecting the Instant Image Generator component of BdThemes, from version n/a through 1.5.4. This issue involves an Unrestricted File Upload vulnerability, which enables attackers to upload a dangerous type of file, such as a web shell, to a web server. By exploiting this weakness, an attacker can gain unauthorized access and potentially control the server, posing a significant risk to sensitive data and system integrity. Organizations using the Instant Image Generator are urged to update to the latest, secure version as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share