CVE-2024-53800

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Jan 7, 2025
CWE ID 829
CWE ID 98

Summary

CVE-2024-53800 is a filename manipulation vulnerability affecting the Rezgo software, specifically versions from n/a to 4.15. An attacker can exploit this PHP Local File Inclusion (LFI) vulnerability by improperly controlling the filename used in include or require statements. This could potentially allow the attacker to access and read sensitive files on the affected system. Successful exploitation of this vulnerability could result in information disclosure, posing a significant risk to the confidentiality of the affected system. Organizations using Rezgo are encouraged to update to a patched version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share