CVE-2024-30500

CVSS 3.1 Score 9.9 of 10 (high)

Details

Published Mar 29, 2024
Updated: Apr 1, 2024
CWE ID 434

Summary

CVE-2024-30500 represents a significant vulnerability affecting the CubeWP – All-in-One Dynamic Content Framework, version n/a through 1.1.12. This issue involves an Unrestricted File Upload with Dangerous Type, enabling attackers to upload arbitrary files to the system without proper restrictions. This can potentially lead to serious security implications, such as data compromise or even unauthorized system access. It is crucial for users to update their CubeWP installation to the latest version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share