CVE-2024-52380
CVSS 3.1 Score 10.0 of 10 (high)
Details
Published Nov 14, 2024
Updated: Nov 15, 2024
CWE ID 434
Summary
CVE-2024-52380 is a newly identified vulnerability affecting Softpulse Infotech's Picsmize application. The issue involves an Unrestricted File Upload vulnerability, enabling attackers to upload a Web Shell to a web server. By exploiting this weakness, cybercriminals can gain unauthorized access and potentially execute malicious code, posing a significant security risk. This vulnerability affects all versions of Picsmize from n/a through 1.0.0.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.