CVE-2024-4172

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Apr 25, 2024
Updated: Jun 4, 2024
CWE ID 22

Summary

CVE-2024-4172 is a newly disclosed vulnerability that affects idCMS 1.35. The issue lies in an unknown functionality of the /admin/admin_cl.php?mudi=revPwd file. An attacker can exploit this vulnerability through cross-site request forgery, allowing them to make unauthorized requests on behalf of the user. This attack can be launched remotely, making it a significant security concern. The exploit for this vulnerability has been made public, increasing the risk of widespread exploitation. The associated identifier for this vulnerability is VDB-261991.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • SKYSEA Client View

Affected Vendors

  • Sky Group

Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future

Note: This is just a basic overview providing quick insights into CVE-2024-4172 information. Gain full access to comprehensive CVE data, third party vulnerabilities, compromised credentials and more with Recorded Future
  • Gain complete coverage of your cyber, third party, and physical attack surface
  • Proactively mitigate threats before they turn into costly attacks
  • Make fast, effective, data-driven decisions