CVE-2025-24650

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Jan 24, 2025
CWE ID 434

Summary

CVE-2025-24650 is a vulnerability affecting Themefic Tourfic, where an Unrestricted File Upload with Dangerous Type allows an attacker to upload a web shell to a web server. This issue, which affects versions from n/a to 2.15.3, poses a significant risk as a web shell grant attackers unauthorized access and control over the affected server. Successful exploitation can lead to various malicious activities, including data theft, website defacement, and further exploitation of other vulnerabilities. It is crucial for users to update to the latest version of Themefic Tourfic to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share