CVE-2024-56050
CVSS 3.1 Score 9.9 of 10 (high)
Details
Published Dec 18, 2024
CWE ID 434
Summary
CVE-2024-56050 is a newly disclosed vulnerability affecting the WPLMS platform from version n/a before 1.9.9.5.3. This issue involves an Unrestricted File Upload vulnerability where an attacker can upload a dangerous file type, such as a web shell, to the web server. As a result, the attacker can gain unauthorized access and control over the affected system. This vulnerability poses a significant risk to the security of the WPLMS platform and demands immediate attention for patching and mitigation measures.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- WP LMS
Affected Vendors
- Proofpoint, Inc.