CVE-2024-24621
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Softaculous Webuzo contains an authentication bypass vulnerability through the password reset functionality. Remote, anonymous attackers can exploit this vulnerability to gain full server access as the root user.
Affected (1)
Products: Softaculous: Webuzo
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.2.9 |
References (2)
Source: disclosures@exodusintel.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.