CVE-2025-4024

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Apr 28, 2025
Updated: Apr 30, 2025
CWE ID 74
CWE ID 89

Summary

CVE-2025-4024 is a newly discovered critical vulnerability in the Placement Management System 1.0. An unknown function within the file /add_drive.php is the culprit, allowing attackers to execute SQL injection through manipulation of the drive_title argument. This vulnerability permits remote exploitation, making it a significant threat. The exploit for this issue has been made public, increasing the risk of attacks. Further investigation suggests that other parameters may also be impacted.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share