CVE-2024-53800
CVSS 3.1 Score 8.1 of 10 (high)
Details
Summary
CVE-2024-53800 is a filename manipulation vulnerability affecting the Rezgo software, specifically versions from n/a to 4.15. An attacker can exploit this PHP Local File Inclusion (LFI) vulnerability by improperly controlling the filename used in include or require statements. This could potentially allow the attacker to access and read sensitive files on the affected system. Successful exploitation of this vulnerability could result in information disclosure, posing a significant risk to the confidentiality of the affected system. Organizations using Rezgo are encouraged to update to a patched version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.