Remote File Inclusion Vulnerability in Spider Themes EazyDocs
CVE-2024-54376
What is CVE-2024-54376?
CVE-2024-54376 is a high-risk Remote File Inclusion (RFI) vulnerability present in the Spider Themes EazyDocs plugin. This vulnerability arises from improper control of the filename in include or require statements within the PHP application, which could allow an attacker to exploit this flaw by injecting malicious scripts into the server. This critical security issue specifically affects EazyDocs versions from n/a to 2.5.5, and if left unpatched, it could lead to unauthorized access, data breaches, or complete server compromise. Organizations using the affected versions are strongly advised to upgrade to the latest release and apply necessary security measures.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
EazyDocs <= 2.5.5
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved