CVE-2024-6470

CVSS 3.1 Score 2.7 of 10 (low)

Details

Published Jul 3, 2024
Updated: Jul 5, 2024
CWE ID 74

Summary

CVE-2024-6470 is a newly disclosed vulnerability affecting playSMS 1.4.3. This issue, rated as problematic, impacts an unspecified functionality within the file /index.php?app=main&inc=feature_inboxgroup&op=list of the Template Handler component. The manipulation of the argument Receiver Number using the input {{`id`}} can result in injection attacks. These attacks can be executed remotely, and the exploit is publicly disclosed. Vendor contact regarding this disclosure did not result in any response. (VDB-270278)

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share