CVE-2024-30500
CVSS 3.1 Score 9.9 of 10 (high)
Details
Published Mar 29, 2024
Updated: Apr 1, 2024
CWE ID 434
Summary
CVE-2024-30500 represents a significant vulnerability affecting the CubeWP – All-in-One Dynamic Content Framework, version n/a through 1.1.12. This issue involves an Unrestricted File Upload with Dangerous Type, enabling attackers to upload arbitrary files to the system without proper restrictions. This can potentially lead to serious security implications, such as data compromise or even unauthorized system access. It is crucial for users to update their CubeWP installation to the latest version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share