CVE-2024-9970

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Oct 15, 2024
Updated: Oct 17, 2024
CWE ID 565

Summary

CVE-2024-9970 is a privilege escalation vulnerability affecting the FlowMaster BPM Plus system from NewType. This issue allows remote attackers, who already have regular privileges, to elevate their access to administrative levels by manipulating a specific cookie. Successful exploitation grants attackers expanded control over the system, potentially leading to unauthorized modifications or gain of sensitive information. Organizations using this software are advised to apply the necessary patch or update as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share