CVE-2024-24621
Estado: ModificadaCrítica (9.8)—
Softaculous Webuzo contains an authentication bypass vulnerability through the password reset functionality. Remote, anonymous attackers can exploit this vulnerability to gain full server access as the root user.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.16%
- Percentil entre todas las CVEs puntuadas: 66
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-697
- CWE-697
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-24621",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-24621",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-07-26T13:47:16.957477Z"
}
}
],
"cvssMetricV2": [
{
"type": "Secondary",
"source": "disclosures@exodusintel.com",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "disclosures@exodusintel.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "disclosures@exodusintel.com",
"affectedData": [
{
"vendor": "Softaculous",
"product": "Webuzo",
"versions": [
{
"status": "affected",
"version": "3.2.1",
"versionType": "semver",
"lessThanOrEqual": "4.2.9"
}
],
"defaultStatus": "unaffected"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:softaculous:webuzo:*:*:*:*:*:*:*:*"
],
"vendor": "softaculous",
"product": "webuzo",
"versions": [
{
"status": "affected",
"version": "3.2.1",
"versionType": "semver",
"lessThanOrEqual": "4.2.9"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-07-25T22:15:05.230",
"references": [
{
"url": "https://blog.exodusintel.com/2024/07/25/softaculous-webuzo-authentication-bypass/",
"tags": [
"Third Party Advisory"
],
"source": "disclosures@exodusintel.com"
},
{
"url": "https://blog.exodusintel.com/2024/07/25/softaculous-webuzo-authentication-bypass/",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "disclosures@exodusintel.com",
"description": [
{
"lang": "en",
"value": "CWE-697"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-697"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Softaculous Webuzo contains an authentication bypass vulnerability through the password reset functionality. Remote, anonymous attackers can exploit this vulnerability to gain full server access as the root user."
},
{
"lang": "es",
"value": "Softaculous Webuzo contiene una vulnerabilidad de omisión de autenticación a través de la funcionalidad de restablecimiento de contraseña. Los atacantes remotos y anónimos pueden aprovechar esta vulnerabilidad para obtener acceso completo al servidor como usuario root."
}
],
"lastModified": "2026-06-17T07:14:40.320",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:softaculous:webuzo:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "359222CD-17E4-411F-951D-6E1A83AF0133",
"versionEndExcluding": "4.2.9"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "disclosures@exodusintel.com"
}