PT-2024-35240 · Hacklog · Hacklog Downloadmanager

Joshua Chan

·

Published

2024-11-19

·

Updated

2024-11-21

·

CVE-2024-52401

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hacklog DownloadManager versions 2.1.4 and earlier
Description A Cross-Site Request Forgery (CSRF) issue in Hacklog DownloadManager allows attackers to upload a web shell to a web server. This can be exploited by attackers to gain unauthorized access to the web server.
Recommendations For Hacklog DownloadManager versions 2.1.4 and earlier, update to version 2.1.5 to resolve the issue. As a temporary workaround, consider restricting access to the DownloadManager to minimize the risk of exploitation.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-52401

Affected Products

Hacklog Downloadmanager