CVE-2024-52401

CVSS 3.1 Score 9.6 of 10 (high)

Details

Published Nov 19, 2024
Updated: Nov 20, 2024
CWE ID 352

Summary

CVE-2024-52401 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Hacklog DownloadManager, from an unspecified version through 2.1.4. An attacker exploiting this issue can upload a web shell to a targeted web server, potentially giving them unauthorized access and control over the server's functionality. This vulnerability poses a significant risk for those using the Hacklog DownloadManager and emphasizes the importance of timely patches to mitigate such threats.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share