CVE-2024-25600 is a critical Code Injection vulnerability in Codeer Limited Bricks Builder versions up to 1.9.6, allowing unauthenticated remote code execution. With a CVSS score of 10.0, it presents a severe risk due to its network-based attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. The vulnerability is actively exploited, with Metasploit modules and Nuclei templates publicly available, and has garnered significant community discussion and media coverage, indicating widespread awareness and potential for malicious use.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Codeer Limited | Bricks Builder | >= n/a, <= 1.9.6CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.