CVE-2024-57052

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jan 27, 2025
Updated: Jan 28, 2025
CWE ID 384

Summary

CVE-2024-57052 is a vulnerability affecting youdiancms versions 9.5.20 and earlier. This issue enables a remote attacker to escalate privileges by exploiting a flaw in the sessionID parameter within the index.php file. Successful exploitation grants the attacker elevated access to the affected system. Users are advised to update their software to a secure version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share