Cyber Posture

CVE-2024-48445

Critical

Published: 04 February 2025

Published
04 February 2025
Modified
15 April 2026
KEV Added
Patch
CVSS Score 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.1193 93.8th percentile
Risk Priority 27 60% EPSS · 20% KEV · 20% CVSS

Description

An issue in compop.ca ONLINE MALL v.3.5.3 allows a remote attacker to execute arbitrary code via the rid, tid, et, and ts parameters.

Security Summary

CVE-2024-48445 is a critical vulnerability in compop.ca ONLINE MALL version 3.5.3 that enables arbitrary code execution. A remote attacker can exploit this issue by manipulating the rid, tid, et, and ts parameters, as detailed in the CVE description published on 2025-02-04. The flaw is associated with CWE-287 (Improper Authentication) and carries a CVSS v3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), reflecting its high severity due to network accessibility, low attack complexity, and lack of prerequisites.

Any unauthenticated remote attacker can exploit this vulnerability without user interaction. Successful exploitation allows the attacker to execute arbitrary code on the targeted system, potentially leading to complete compromise with high impacts on confidentiality, integrity, and availability.

Advisories and further details, including potential patches or workarounds, are available in the referenced PacketStorm publication at https://packetstorm.news/files/id/188996/. Security practitioners should review this source for mitigation guidance specific to compop.ca ONLINE MALL v3.5.3.

Details

CWE(s)
CWE-287

References