CVE-2024-57685

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Feb 24, 2025
Updated: Feb 25, 2025
CWE ID 77

Summary

CVE-2024-57685 is a newly disclosed vulnerability affecting SparkShop versions 1.1.7 and older. This issue grants remote attackers the ability to execute arbitrary code by exploiting a vulnerability in the application's handling of Phar files. By crafting a malicious Phar file, an attacker can potentially gain unauthorized access to the system and execute malicious code, resulting in potential data loss or unauthorized system modifications. Users are strongly advised to update their SparkShop installations to the latest version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share