CVE-2024-9903
CVSS 3.1 Score 4.7 of 10 (medium)
Details
Summary
CVE-2024-9903 is a critical vulnerability affecting versions up to 1.2.0 of 07FLYCMS, 07FLY-CMS, and 07FlyCRM, specifically in the fileUpload function found in the /admin/File/fileUpload file. This vulnerability allows for unrestricted file uploads that can be exploited remotely, posing a significant risk to organizations using these products. The exploit has been publicly disclosed, increasing its likelihood of being leveraged by attackers. There was no successful communication with the vendor prior to the CVE assignment due to an inactive email address. To remediate this issue, organizations should update their software to a patched version or implement strict controls on file uploads to mitigate potential attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.