CVE-2024-24621

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/07/2024
Last modified:
30/07/2024

Description

Softaculous Webuzo contains an authentication bypass vulnerability through the password reset functionality. Remote, anonymous attackers can exploit this vulnerability to gain full server access as the root user.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:softaculous:webuzo:*:*:*:*:*:*:*:* 4.2.9 (excluding)