CVE-2024-8465
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-8465 is an SQL injection vulnerability affecting the product identified as 'tYxz11', which allows attackers to exploit the user_id parameter in the /jobportal/admin/user/controller.php file. This flaw can enable unauthorized access to sensitive data stored within the system, posing a significant risk to an organization’s confidentiality. The vulnerability has a high severity rating with a CVSS score of 7.5, indicating that it requires no special privileges or user interaction for exploitation and can be executed over a network with low complexity. To remediate this issue, organizations should implement proper input validation and sanitization measures to prevent untrusted data from being executed as SQL commands. Failure to address this vulnerability could lead to severe data breaches and compromise the integrity of sensitive information within their systems.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.