CVE-2024-1258
CVSS 3.1 Score 5.9 of 10 (medium)
Details
Summary
CVE-2024-1258 is a recently disclosed vulnerability affecting Juanpao JPShop up to version 1.5.02. This issue lies within an unknown functionality of the file api/config/params.php in the API component. A hard-coded cryptographic key is utilized when the JWT_KEY_ADMIN argument is manipulated, posing a potential security risk. The complexity of an attack is considered high, with exploitation appearing to be difficult. However, the exploit has been made public, increasing the potential for malicious activity. Vulnerability database VDB has assigned the identifier VDB-252997 to this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.