Remote File Inclusion Vulnerability in Spider Themes EazyDocs
CVE-2024-54376
7.5HIGH
Summary
CVE-2024-54376 is a high-risk Remote File Inclusion (RFI) vulnerability present in the Spider Themes EazyDocs plugin. This vulnerability arises from improper control of the filename in include or require statements within the PHP application, which could allow an attacker to exploit this flaw by injecting malicious scripts into the server. This critical security issue specifically affects EazyDocs versions from n/a to 2.5.5, and if left unpatched, it could lead to unauthorized access, data breaches, or complete server compromise. Organizations using the affected versions are strongly advised to upgrade to the latest release and apply necessary security measures.
Affected Version(s)
EazyDocs <= 2.5.5
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
kslatz (Patchstack Alliance)