CVE-2024-54376
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-54376 is a newly disclosed vulnerability affecting Spider-themes EazyDocs. This issue involves an Improper Control of Filename for Include/Require Statement in the PHP program, also known as a PHP Remote File Inclusion (RFI) vulnerability. The flaw allows an attacker to include and execute arbitrary PHP files on the targeted server, potentially leading to unauthorized access, data theft, or server takeover. The vulnerability has been identified in EazyDocs versions from n/a through 2.5.5. Users are advised to update their installations as soon as possible to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.