CVE-2024-34082
Getgrav
CVE-2024-34082 is a critical vulnerability in the Grav CMS platform that allows low-privilege users to read sensitive server files. This flaw exposes user account information, including hashed passwords and 2FA secrets. Despite a CVSS score of 9.9, SOCRadar's Vulnerability Risk Score (SVRS) is 36, which suggests a lower level of real-world exploitability at this time, although still requiring attention. The vulnerability, found in Grav versions prior to 1.7.46, permits attackers to compromise accounts and access any file on the web server. Successfully exploiting CVE-2024-34082 can lead to complete account takeover, even of administrator accounts, by resetting passwords or cracking hashed passwords. Given the potential for significant data breaches and system compromise, applying the patch in version 1.7.46 is essential to mitigate this security risk. While not immediately critical based on the SVRS, proactive patching is advised.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.