CVE-2024-52598

CVSS 3.1 Score 7.5 of 10 (high)

Attack Complexity low
Confidentiality high
Integrity none
Availability none
Scope unchanged
Privileges Required none

Details

Published Nov 20, 2024
Updated: Nov 21, 2024
CWE ID 918
CWE ID 79
CWE ID 80

Summary

CVE-2024-11486 is a recently disclosed vulnerability affecting the Code4Berry Decoration Management System 1.0. The issue lies within the User Permission Handler component, specifically the file /decoration/admin/user_permission.php. This vulnerability is classified as problematic, allowing permission manipulation that can be exploited remotely. The exploit has been made public, increasing the risk for potential attacks. Despite early notification, the vendor has not responded to address this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share