PT-2025-23180 · Unknown · Openknowledgemaps Head Start
Published
2025-05-29
·
Updated
2025-05-30
·
CVE-2024-51392
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenKnowledgeMaps Headstart version 7
Description
An issue in OpenKnowledgeMaps Headstart allows a remote attacker to escalate privileges via the
url parameter of the "getPDF.php" component.Recommendations
For OpenKnowledgeMaps Headstart version 7, consider disabling the
getPDF.php component or restricting access to it until a patch is available. Avoid using the url parameter in the affected component to minimize the risk of exploitation.Exploit
Fix
LPE
Improper Privilege Management
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openknowledgemaps Head Start