CVE-2024-56045

CVSS 3.1 Score 9.3 of 10 (high)

Details

Published Dec 31, 2024
CWE ID 35

Summary

CVE-2024-56045 is a newly disclosed vulnerability affecting the WPLMS learning management system from VibeThemes. This issue involves a Path Traversal vulnerability, which can be exploited by an attacker to access unintended files by manipulating the file path. The specific vulnerability occurs when the system fails to adequately filter certain character sequences in a file path, allowing potential malicious navigation. This vulnerability affects WPLMS versions prior to 1.9.9.5, posing a risk to systems that have not yet been updated. Successful exploitation could result in unauthorized access to sensitive data or potential system compromise.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share