CVE-2024-10524
Last modified
CVE-2024-10524 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the URL are vulnerable. In these cases attackers can enter crafted credentials which will cause Wget to access an arbitrary host.. EPSS estimates a 1.12% chance of exploitation in the next 30 days.
Description
Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the URL are vulnerable. In these cases attackers can enter crafted credentials which will cause Wget to access an arbitrary host.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-10524?
How severe is CVE-2024-10524?
How do I fix CVE-2024-10524?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-10519The Wishlist for WooCommerce: Multi Wishlists Per Customer P…6.1
- CVE-2024-1052Boundary and Boundary Enterprise (“Boundary”) is vulnerable …8
- CVE-2024-10520The WP Project Manager plugin for WordPress is vulnerable to…5.3
- CVE-2024-10521The WordPress Contact Forms by Cimatti plugin for WordPress …4.3
- CVE-2024-10522The Co-marquage service-public.fr plugin for WordPress is vu…6.1
- CVE-2024-10523This vulnerability exists in TP-Link IoT Smart Hub due to st…4.6
- CVE-2024-10525In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if …9.8
- CVE-2024-10526Rapid7 Velociraptor MSI Installer versions below 0.73.3 suff…8.6
- CVE-2024-10527The Spacer plugin for WordPress is vulnerable to unauthorize…3.1
- CVE-2024-10528The Ultimate Member – User Profile, Registration, Login, Mem…4.3
- CVE-2024-10529The Kognetiks Chatbot for WordPress plugin for WordPress is …5.3
- CVE-2024-1053The Event Tickets and Registration plugin for WordPress is v…4.3
Are you affected by CVE-2024-10524?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
