Remote File Inclusion Vulnerability in Spider Themes EazyDocs
CVE-2024-54376
7.5HIGH
What is CVE-2024-54376?
CVE-2024-54376 is a high-risk Remote File Inclusion (RFI) vulnerability present in the Spider Themes EazyDocs plugin. This vulnerability arises from improper control of the filename in include or require statements within the PHP application, which could allow an attacker to exploit this flaw by injecting malicious scripts into the server. This critical security issue specifically affects EazyDocs versions from n/a to 2.5.5, and if left unpatched, it could lead to unauthorized access, data breaches, or complete server compromise. Organizations using the affected versions are strongly advised to upgrade to the latest release and apply necessary security measures.
Affected Version(s)
EazyDocs <= 2.5.5