CVE-2024-21622
Craftcms
CVE-2024-21622 is a privilege escalation vulnerability in the Craft CMS platform. Specifically, this vulnerability affects Craft versions 3.x (prior to 3.9.6) and 4.x (prior to 4.4.16) under specific user permission configurations. The vulnerability could allow an attacker to gain higher-level access than intended, potentially leading to unauthorized modifications or data breaches. The CVSS score is 8.8, indicating a high severity, however, the SOCRadar Vulnerability Risk Score (SVRS) of 30 suggests a lower level of immediate risk, potentially due to limited exploitability or a lack of widespread active exploitation in the wild. Users of Craft CMS are strongly advised to upgrade to version 3.9.6 or 4.4.16 (or later) to mitigate this vulnerability. Neglecting this update could expose systems to potential security risks. While the SVRS is lower, the potential impact of privilege escalation warrants prompt remediation.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.