CVE-2024-57433
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Jan 31, 2025
Updated: Feb 3, 2025
CWE ID 863
Summary
CVE-2024-57433: The popular macrozheng mall-tiny e-commerce platform version 1.0.1 contains a security flaw. After a user logs out, their access token remains active, allowing unauthorized access to fetch information as if they were still logged in. This issue exposes sensitive data and could lead to potential data breaches. Users are advised to update to the latest version or implement additional security measures until a fix is available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share