CVE-2024-25298: Code Injection
Published Feb 17, 2024
·Updated
An issue was discovered in REDAXO version 5.15.1, allows attackers to execute arbitrary code and obtain sensitive information via modules.modules.php.
Affected Software
2 affected components
composer/redaxo/source<=5.15.1
REDAXO REDAXO=5.15.1
Event History
Feb 17, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·06:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-25298?
CVE-2024-25298 is classified as a critical vulnerability due to its potential to allow arbitrary code execution.
2
How do I fix CVE-2024-25298?
To remediate CVE-2024-25298, upgrade REDAXO to version 5.15.2 or later.
3
What systems are affected by CVE-2024-25298?
CVE-2024-25298 affects REDAXO version 5.15.1 and previous versions.
4
What type of vulnerability is CVE-2024-25298?
CVE-2024-25298 is a remote code execution vulnerability.
5
Can CVE-2024-25298 lead to data breaches?
Yes, CVE-2024-25298 can potentially lead to data breaches by allowing unauthorized access to sensitive information.