CVE-2024-52401
CVSS 3.1 Score 9.6 of 10 (high)
Details
Published Nov 19, 2024
Updated: Nov 20, 2024
CWE ID 352
Summary
CVE-2024-52401 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Hacklog DownloadManager, from an unspecified version through 2.1.4. An attacker exploiting this issue can upload a web shell to a targeted web server, potentially giving them unauthorized access and control over the server's functionality. This vulnerability poses a significant risk for those using the Hacklog DownloadManager and emphasizes the importance of timely patches to mitigate such threats.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share