CVE-2024-22567
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Feb 5, 2024
Updated: Feb 14, 2024
CWE ID 434
Summary
CVE-2024-22567 is a file upload vulnerability affecting MCMS 5.3.5. An attacker can exploit this vulnerability by sending a crafted POST request to the /ms/file/upload.do endpoint, allowing them to upload arbitrary files to the system. Successful exploitation could lead to unauthorized access or data theft, potentially causing significant damage to the affected organization. It is strongly recommended that MCMS 5.3.5 users apply the necessary patches or upgrades to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share