CVE-2024-9278

CVSS 2.0 Score 5.8 of 10 (medium)

Details

Published Sep 27, 2024
Updated: Sep 30, 2024
CWE ID 434

Summary

CVE-2024-9278 is a critical vulnerability impacting HuankeMao SCRM versions up to 0.0.3. This issue lies in the function upload_domain_verification_file of the WxkConfig.php component in the Administrator Backend. An attacker can exploit this flaw by manipulating the argument domain_verification_file, enabling them to perform unrestricted file uploads. The vulnerability is remote, meaning it can be exploited from outside the affected system. The exploit for this vulnerability has been made public, increasing the risk of potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share