Image API Vulnerability Allows Authenticated Attackers to Execute Arbitrary Code
CVE-2024-24551

Currently unrated

Key Information:

Vendor

Bludit

Status
Vendor
CVE Published:
24 June 2024

What is CVE-2024-24551?

A security vulnerability has been identified in Bludit, allowing authenticated attackers to execute arbitrary code through the Image API. This vulnerability arises from improper handling of file uploads, enabling malicious actors to upload and execute PHP files.

Affected Version(s)

Bludit Linux v3.9.0 beta 1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andreas Pfefferle, Redguard AG
.