CVE-2024-53636
CVSS 3.1 Score 6.4 of 10 (medium)
Details
Summary
CVE-2024-53636 is a newly disclosed vulnerability affecting the Serosoft Academia Student Information System (SIS) EagleR version 1.0.118. This vulnerability enables attackers to upload arbitrary files through the writefile.php function, thanks to an improper validation of the filePath parameter. Attackers can exploit this weakness to execute malicious code on the targeted system, potentially leading to serious security breaches and unauthorized access. Organizations utilizing the SIS EagleR software are urged to apply the necessary patches as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.