CVE-2024-56216

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Dec 31, 2024
Updated: Feb 7, 2025
CWE ID 829
CWE ID 98

Summary

CVE-2024-56216 is a new vulnerability affecting Themify Builder, where an improper control of filename for include/require statement in PHP programs allows for Local File Inclusion. This issue, known as PHP Remote File Inclusion, grants attackers the ability to include arbitrary files on the affected system. As a result, this vulnerability poses a significant security risk for Themify Builder versions from n/a through 7.6.3. Successful exploitation can lead to data exposure, unauthorized system access, or even complete system takeover. It is crucial that users of these affected versions apply patches or upgrades as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share