Arbitrary File Upload Vulnerability in LEPTON v7.0.0
CVE-2024-24399
7.2HIGH
What is CVE-2024-24399?
An arbitrary file upload vulnerability exists in LEPTON version 7.0.0, which enables authenticated attackers to upload malicious PHP code to the backend/languages/index.php area. Once the code is uploaded, it can be executed by the attacker, potentially leading to unauthorized access and full control over the affected system. This vulnerability underscores the importance of implementing strict input validation and access controls to safeguard against such security threats.
