Initiatives for
As the national authority for Cybersecurity the CCB has developed several initiatives for specific publics which are presented here.
Reference:
Advisory #2024-276
Version:
1.0
Affected software:
Valor Apps Easy Folder Listing Pro (before: 3.8 and 4.5)
Type:
Deserialization
CVE/CVSS:
CVE-2024-11145, Score: 9.8, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
https://www.valorapps.com/web-products/easy-folder-listing-pro.html
The vulnerability presents a significant risk due to its potential for remote code execution, which could allow attackers to gain control over affected systems.
Furthermore, the vulnerability has a high impact on confidentiality, integrity, and availability.
Valor Apps Easy Folder Listing Pro contains a deserialization vulnerability, a critical flaw that arises when untrusted data is processed during deserialization. This vulnerability allows an unauthenticated, remote attacker to send specially crafted input that can manipulate the deserialization process. By doing so, the attacker can execute arbitrary code on the server with the same privileges as the Joomla! application.
Exploitation Impact:
Patch
The Centre for Cybersecurity Belgium strongly recommends installing updates for vulnerable devices with the highest priority, after thorough testing.
Monitor/Detect
The CCB recommends organizations upscale monitoring and detection capabilities to identify any related suspicious activity, ensuring a swift response in case of an intrusion.
In case of an intrusion, you can report an incident via: https://ccb.belgium.be/cert/report-incident
While patching appliances or software to the newest version may provide safety from future exploitation, it does not remediate historic compromise.
https://nvd.nist.gov/vuln/detail/CVE-2024-11145