CVE-2024-24622: Softaculous Webuzo
High severity, CVSS 8.8. EPSS: 1.9% chance of exploitation in the next 30 days.
Softaculous Webuzo contains a command injection in the password reset functionality. A remote, authenticated attacker can exploit this vulnerability to gain code execution on the system.
Affected products
- Softaculous Webuzo: before 4.2.9 (fixed in 4.2.9)
Published 2024-07-25. Last modified 2026-06-17.