CVE-2024-22523: Fuwushe Ifair

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

Directory Traversal vulnerability in Qiyu iFair version 23.8_ad0 and before, allows remote attackers to obtain sensitive information via uploadimage component.

Affected products

  • Fuwushe Ifair: up to and including 23.8_ad0

Published 2024-01-30. Last modified 2026-06-17.