CVE-2024-9294

CVSS 2.0 Score 6.5 of 10 (medium)

Details

Published Sep 27, 2024
Updated: Sep 30, 2024
CWE ID 89

Summary

CVE-2024-9294 is a critical vulnerability affecting the dingfanzu CMS up to the version 29d67d9044f6f93378e6eb6ff92272217ff7225c. This issue lies within the file saveNewPwd.php, where a sql injection vulnerability can be triggered by manipulating the argument username. The exploit can be executed remotely, and its details have been disclosed to the public. Given the continuous delivery with rolling releases used by this product, no specific version information regarding affected or updated releases has been provided.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share