CVE-2024-54362
CVSS 3.1 Score 8.1 of 10 (high)
Details
Summary
CVE-2024-54362 is a newly identified path traversal vulnerability affecting the NotFound GetShop ecommerce platform, impacting versions from n/a to 1.3. This issue allows unauthorized users to traverse and potentially gain unauthorized access to restricted files or directories by manipulating the file path input. Such a vulnerability could lead to sensitive data leakage, unauthorized system access, or other malicious activities if successfully exploited. Users are advised to update their GetShop ecommerce installations to the latest version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.