CVE-2024-7500

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Aug 6, 2024
Updated: Sep 11, 2024
CWE ID 434

Summary

CVE-2024-7500 is a critical vulnerability affecting the Airline Reservation System 1.0. The issue lies in the save_settings function of the admin/admin_class.php file. An attacker can exploit this flaw by manipulating the img argument to perform unrestricted file uploads. Due to remote access capabilities, this vulnerability can be exploited remotely, making it a significant security risk. The exploit for this vulnerability, identified as VDB-273626, has been disclosed to the public, increasing the urgency for affected organizations to take corrective measures.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share