CVE-2024-8876

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Sep 15, 2024
Updated: Sep 20, 2024
CWE ID 22

Summary

CVE-2024-8876 is a vulnerability affecting TpMeCMS versions up to 1.3.3.1, specifically impacting the functionality associated with the file /index/ajax/lang. This flaw allows for path traversal through manipulation of the 'lang' argument, enabling remote exploitation. Given its low attack complexity and high confidentiality impact, this vulnerability poses significant risks to organizations using affected products such as yomgYL and yoK7Ak. To mitigate this threat, it is crucial for users to upgrade to version 1.3.3.2 or later promptly. The exploit has been publicly disclosed, increasing the urgency for remediation efforts.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share