CVE-2024-2566
CVSS 3.1 Score 7.3 of 10 (high)
Details
Summary
CVE-2024-2566 is a newly disclosed critical vulnerability affecting the Fujian Kelixin Communication Command and Dispatch Platform up to version 20240313. The issue lies in an unknown functionality of the file api/client/get_extension_yl.php, where manipulation of the argument imei can lead to SQL injection. This vulnerability can be exploited remotely, allowing attackers to gain unauthorized access to sensitive data or even take control of the system. The exploit for this vulnerability has been made public, increasing the risk of widespread attacks. The vulnerability has been assigned the identifier VDB-257065 by the Vulnerability Database.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.