CVE-2024-9903

CVSS 3.1 Score 4.7 of 10 (medium)

Details

Published Oct 12, 2024
Updated: Oct 15, 2024
CWE ID 434

Summary

CVE-2024-9903 is a critical vulnerability affecting versions up to 1.2.0 of 07FLYCMS, 07FLY-CMS, and 07FlyCRM, specifically in the fileUpload function found in the /admin/File/fileUpload file. This vulnerability allows for unrestricted file uploads that can be exploited remotely, posing a significant risk to organizations using these products. The exploit has been publicly disclosed, increasing its likelihood of being leveraged by attackers. There was no successful communication with the vendor prior to the CVE assignment due to an inactive email address. To remediate this issue, organizations should update their software to a patched version or implement strict controls on file uploads to mitigate potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share