CVE-2024-38294: Critical severity hazelcast jet vulnerability
Published Jun 13, 2024
·Updated
ALCASAR before 3.6.1 allows emailregistrationback.php remote code execution.
Affected Software
1 affected component
ALCASAR ALCASAR<3.6.1
Event History
Jun 13, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-38294?
CVE-2024-38294 is rated as a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2024-38294?
To mitigate CVE-2024-38294, upgrade ALCASAR to version 3.6.1 or later.
3
What does CVE-2024-38294 affect?
CVE-2024-38294 affects ALCASAR versions prior to 3.6.1.
4
What type of attack does CVE-2024-38294 enable?
CVE-2024-38294 enables remote code execution attacks through the email_registration_back.php script.
5
Is there a patch available for CVE-2024-38294?
Yes, a patch is available by upgrading to ALCASAR version 3.6.1 or newer.