CVE-2024-57547

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 27, 2025
Updated: Jan 28, 2025
CWE ID 732

Summary

CVE-2024-57547 is a newly disclosed vulnerability affecting CMSimple version 5.16. This issue involves insecure permissions, which enable a remote attacker to gain unauthorized access to sensitive information. By crafting a specific script, an attacker can download php backup files, potentially exposing confidential data. This vulnerability poses a significant risk and requires immediate attention from CMSimple users running version 5.16. It is recommended that they upgrade to a secure version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share