CVE-2024-1750 is a critical deserialization vulnerability in TemmokuMVC up to version 2.3, specifically within the get_img_url/img_replace function of its Image Download Handler. This flaw allows for remote code execution with high impact on confidentiality, integrity, and availability. While the attack complexity and exploitability are rated as high and difficult, respectively, public exploit code exists. Despite this, there is no evidence of active exploitation, and the vulnerability has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.3CPE matchmatch criteria | cpe:2.3:a:temmokumvc:temmokumvc:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.