CVE-2024-53523
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-53523 is a newly disclosed vulnerability in JSFinder's commit d70ab9bc5221e016c08cffaf0d9ac79646c90645. The issue lies within the find_by_file function, which is susceptible to Directory Traversal attacks. An attacker can exploit this vulnerability by manipulating the input data to access files outside the intended directory, potentially leading to unauthorized data access or system compromise. The exact implications and potential impact of this vulnerability are currently unknown, but it poses a significant threat to any systems utilizing the affected JSFinder version. Users are advised to update to the latest, non-vulnerable version as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.