CVE-2024-57433

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 31, 2025
Updated: Feb 3, 2025
CWE ID 863

Summary

CVE-2024-57433: The popular macrozheng mall-tiny e-commerce platform version 1.0.1 contains a security flaw. After a user logs out, their access token remains active, allowing unauthorized access to fetch information as if they were still logged in. This issue exposes sensitive data and could lead to potential data breaches. Users are advised to update to the latest version or implement additional security measures until a fix is available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share