CVE-2024-24621
CVE-2024-24621
Título es
CVE-2024-24621
Jue, 25/07/2024 – 22:15
Tipo
CWE-697
Gravedad v2.0
10.00
Gravedad 2.0 Txt
HIGH
Título en
CVE-2024-24621
Descripción en
Softaculous Webuzo contains an authentication bypass vulnerability through the password reset functionality. Remote, anonymous attackers can exploit this vulnerability to gain full server access as the root user.
26/07/2024
26/07/2024
Vector CVSS:3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vector CVSS:2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Gravedad 3.1 (CVSS 3.1 Base Score)
9.80
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
CRITICAL
Enviar en el boletín
Off