Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-2411 — AI Deep Analysis Summary

CVSS 9.8 · Critical

Q1What is this vulnerability? (Essence + Consequences)

🚨 **Essence**: Local File Inclusion (LFI) in MasterStudy LMS. <br>💥 **Consequences**: Attackers include & execute arbitrary PHP files. Total server compromise possible. 📉

Q2Root Cause? (CWE/Flaw)

🛡️ **Root Cause**: CWE-98 (Improper Control of Filename for Include/Require). <br>🔍 **Flaw**: Input validation failure allows path traversal. 📂

Q3Who is affected? (Versions/Components)

👥 **Affected**: WordPress Plugin: MasterStudy LMS. <br>📦 **Version**: 3.3.0 and earlier. <br>🏢 **Vendor**: stylemix. ⚠️

Q4What can hackers do? (Privileges/Data)

🕵️ **Hackers Can**: Execute ANY PHP code on the server. <br>🔓 **Privileges**: Full control (Root/Admin). <br>💾 **Data**: Read/Write/Modify all files. 📂

Q5Is exploitation threshold high? (Auth/Config)

📉 **Threshold**: LOW. <br>🔑 **Auth**: None required (Unauthenticated). <br>🌐 **Access**: Network accessible. 🚪

Q6Is there a public Exp? (PoC/Wild Exploitation)

📜 **Public Exp?**: No PoCs listed in data. <br>🔥 **Wild Exp**: Unconfirmed. <br>⚠️ **Risk**: CVSS 9.8 implies high exploitability. 🎯

Q7How to self-check? (Features/Scanning)

🔍 **Self-Check**: Scan for MasterStudy LMS v3.3.0-. <br>🧪 **Test**: Attempt LFI payloads on plugin endpoints. <br>📊 **Tool**: Use WPScan or Nuclei templates. 🛠️

Q8Is it fixed officially? (Patch/Mitigation)

✅ **Fixed?**: Yes. <br>📦 **Patch**: Update to version > 3.3.0. <br>🔗 **Ref**: StyleMix changelog v3.3.1. 🔄

Q9What if no patch? (Workaround)

🚧 **No Patch?**: Disable plugin immediately. <br>🔒 **Mitigate**: Restrict file inclusion via WAF rules. <br>👀 **Monitor**: Log for suspicious include requests. 📝

Q10Is it urgent? (Priority Suggestion)

🚨 **Urgency**: CRITICAL. <br>🔥 **Priority**: Patch NOW. <br>📈 **CVSS**: 9.8 (High). <br>⏳ **Time**: Act within 24h. ⚡