CVE-2024-52598
CVSS 3.1 Score 7.5 of 10 (high)
Attack Complexity low
Confidentiality high
Integrity none
Availability none
Scope unchanged
Privileges Required none
Details
Published Nov 20, 2024
Updated: Nov 21, 2024
CWE ID 918
CWE ID 79
CWE ID 80
Summary
CVE-2024-11486 is a recently disclosed vulnerability affecting the Code4Berry Decoration Management System 1.0. The issue lies within the User Permission Handler component, specifically the file /decoration/admin/user_permission.php. This vulnerability is classified as problematic, allowing permission manipulation that can be exploited remotely. The exploit has been made public, increasing the risk for potential attacks. Despite early notification, the vendor has not responded to address this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.