PT-2024-20481 · Softaculous · Softaculous Webuzo

Exodus Intelligence

·

Published

2024-07-25

·

Updated

2024-07-30

·

CVE-2024-24621

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Softaculous Webuzo (affected versions not specified)
Description The issue allows remote, anonymous attackers to exploit an authentication bypass vulnerability through the password reset functionality, potentially gaining full server access as the root user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2024-24621

Affected Products

Softaculous Webuzo