CVE-2024-24621: Softaculous Webuzo Authentication Bypass
Published Jul 25, 2024
·Updated
Softaculous Webuzo contains an authentication bypass vulnerability through the password reset functionality. Remote, anonymous attackers can exploit this vulnerability to gain full server access as the root user.
Affected Software
1 affected component
Softaculous Webuzo<4.2.9
Event History
Jul 25, 2024
CVE Published
via MITRE·09:44 PM
Data Sourced
via MITRE·09:44 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-24621?
CVE-2024-24621 is classified as a critical vulnerability due to its potential to provide full root access to attackers.
2
How do I fix CVE-2024-24621?
To fix CVE-2024-24621, update Softaculous Webuzo to version 4.2.9 or higher immediately.
3
Who is affected by CVE-2024-24621?
CVE-2024-24621 affects users of Softaculous Webuzo versions prior to 4.2.9.
4
What type of vulnerability is CVE-2024-24621?
CVE-2024-24621 is an authentication bypass vulnerability that can be exploited via the password reset functionality.
5
Can CVE-2024-24621 be exploited remotely?
Yes, CVE-2024-24621 can be exploited by remote, anonymous attackers.