CVE-2024-51919

Published Jan 21, 2025

Last updated a month ago

Overview

Description
Unrestricted Upload of File with Dangerous Type vulnerability in NotFound Fancy Product Designer. This issue affects Fancy Product Designer: from n/a through 6.4.3.
Source
audit@patchstack.com
NVD status
Received

Risk scores

CVSS 3.1

Type
Secondary
Base score
9
Impact score
6
Exploitability score
2.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

audit@patchstack.com
CWE-434

Social media

Hype score
Not currently trending
  1. [CVE-2024-51919: CRITICAL] Unrestricted Upload of File with Dangerous Type vulnerability in NotFound Fancy Product Designer. This issue affects Fancy Product Designer: from n/a through 6.4.3.#cybersecurity,#vulnerability https://t.co/PGjz6LecKW https://t.co/s3NIQf7xyu

    @CveFindCom

    21 Jan 2025

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2024-51919 Unrestricted Upload of File with Dangerous Type vulnerability in NotFound Fancy Product Designer. This issue affects Fancy Product Designer: from n/a through 6.4.3. https://t.co/1dufvFKeHG

    @CVEnew

    21 Jan 2025

    243 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  3. WordPress Fancy Product Designer の脆弱性 CVE-2024-51919/51818:20,000以上のサイトが未パッチ! https://t.co/6OzKsbtaDM WooCommerce 用に開発された、WordPress の Fancy Product Designer… https://t.co/FuXwChAyR5

    @iototsecnews

    20 Jan 2025

    84 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2024-51919,CVE-2024-51818 alert 🚨 Wordpress Plugin Fancy Product Arbitrary File Upload and Unauthenticated SQL Injection The vulnerability is actively exploited in the wild and has been integrated into Patrowl. Our customers assets are protected. 🦉 #CyberSecurity #Wordpress

    @Patrowl_io

    9 Jan 2025

    49 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. WordPressの有料プラグインFancy Product Designerに重大(Critical)な脆弱性。2024/3/18報告だが未修正。CVE-2024-51919はCVSSスコア9.0で、遠隔コード実行につながる未認証での任意ファイルアップロード。CVE-2024-51818はCVSSスコア9.3で、未認証でのSQLインジェクション。 https://t.co/db5oruISbn

    @__kokumoto

    8 Jan 2025

    601 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes