PT-2024-35268 · Ads Pro · Ads Booster

Dimas Maulana

·

Published

2024-11-18

·

Updated

2024-11-20

·

CVE-2024-52428

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ads Booster by Ads Pro versions 1.12 and earlier
Description The issue is related to improper control of filename for include/require statement in PHP program, also known as PHP Remote File Inclusion. This allows PHP Local File Inclusion. The impact of this issue is code execution.
Recommendations For Ads Booster by Ads Pro versions 1.12 and earlier: Update the plugin as soon as possible or remove it if unused. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2024-52428

Affected Products

Ads Booster