First published: Mon Jan 27 2025(Updated: )
An issue in youdiancms v.9.5.20 and before allows a remote attacker to escalate privileges via the sessionID parameter in the index.php file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
YouDianCMS | <9.5.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-57052 has not been assigned a CVSS score, but it allows a remote attacker to escalate privileges which indicates a potentially high severity.
To fix CVE-2024-57052, update to YouDianCMS version 9.5.21 or later which addresses the vulnerability.
CVE-2024-57052 affects YouDianCMS version 9.5.20 and earlier versions.
CVE-2024-57052 enables remote attackers to escalate privileges via the sessionID parameter.
CVE-2024-57052 is found in the index.php file of YouDianCMS.