CVE-2024-24525: Epoint Epointwebbuilder

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

An issue in EpointWebBuilder 5.1.0-sp1, 5.2.1-sp1, 5.4.1 and 5.4.2 allows a remote attacker to execute arbitrary code via the infoid parameter of the URL.

Affected products

  • Epoint Epointwebbuilder: version 5.1.0 only; version 5.2.1 only; version 5.4.1 only; version 5.4.2 only

Published 2024-02-29. Last modified 2026-06-17.