CVE-2024-57241

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Feb 11, 2025
Updated: Feb 18, 2025
CWE ID 601

Summary

CVE-2024-57241 is a newly identified vulnerability affecting Dedecms 5.71sp1 and older versions. This issue arises due to a logic error in the web application, which fails to properly judge input GET requests. Consequently, URL redirection occurs, potentially exposing users to security risks such as phishing attacks or malware infections. Attackers can exploit this vulnerability by crafting malicious URLs and luring users to visit them, leading to unintended and potentially harmful destinations. To mitigate this risk, users are advised to update their Dedecms installation to the latest version as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share