PT-2024-28014 · Xenforo · Xenforo

Egidio Romano

+1

·

Published

2024-06-16

·

Updated

2024-08-20

·

CVE-2024-38458

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Xenforo versions prior to 2.2.16
Description The issue allows code injection.
Recommendations For versions prior to 2.2.16, update to version 2.2.16 or later to resolve the issue.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-38458

Affected Products

Xenforo