Point Maker Includes Remote File Inclusion Vulnerability
CVE-2024-49317
What is CVE-2024-49317?
An improper control of filename for Include/Require statement vulnerability exists in the ZIPANG Point Maker plugin, which allows attackers to exploit PHP Local File Inclusion. This security flaw enables unauthorized users to include files from the server's filesystem, potentially leading to unauthorized access and the execution of malicious code. The vulnerability affects all versions from n/a to 0.1.4, making it crucial for users of the Point Maker plugin to assess their environment and apply remedial measures to secure their applications.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Point Maker <= 0.1.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved