CVE-2024-54270
CVSS 3.1 Score 8.1 of 10 (high)
Details
Summary
CVE-2024-54270 is a new vulnerability affecting the Axeptio platform. This issue involves improper control of filename for include/require statements in PHP programs, leading to a Local File Inclusion (LFI) vulnerability. attackers can exploit this vulnerability in Axeptio versions from n/a to 2.5.3 to gain unauthorized access to sensitive files on the targeted system. This can result in data theft, unauthorized system access, or other malicious activities. Users are strongly advised to update their Axeptio installations to the latest patched version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.