CVE-2024-24291: Medium severity YzmCMS YzmCMS vulnerability
Published Feb 6, 2024
·Updated
An issue in the component /member/index/login of yzmcms v7.0 allows attackers to direct users to malicious sites via a crafted URL.
Affected Software
1 affected component
YzmCMS YzmCMS=7.0
Event History
Feb 6, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-24291?
CVE-2024-24291 is considered a significant vulnerability that can lead to phishing attacks by redirecting users to malicious websites.
2
How do I fix CVE-2024-24291?
To mitigate CVE-2024-24291, it is recommended to immediately update to the latest version of Yzmcms or implement input validation on URLs.
3
What kind of attacks can CVE-2024-24291 enable?
CVE-2024-24291 can enable attackers to perform phishing attacks by redirecting users through crafted URLs.
4
Is CVE-2024-24291 exploitable in specific conditions?
Yes, CVE-2024-24291 is exploitable whenever a user interacts with untrusted URLs in the Yzmcms v7.0 application.
5
What systems are affected by CVE-2024-24291?
CVE-2024-24291 affects Yzmcms version 7.0, compromising its login component.