Arbitrary File Upload Vulnerability in /admin/upgrade
CVE-2024-25414

9.8CRITICAL

Key Information:

Vendor

CSZ CMS

Status
Vendor
CVE Published:
16 February 2024

What is CVE-2024-25414?

An arbitrary file upload vulnerability in the /admin/upgrade feature of CSZ CMS v1.3.0 permits attackers to upload specially crafted Zip files, which could enable code execution on the server. This flaw poses significant risks as it allows unauthorized access and manipulation of server files, which can be exploited for malicious activities.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.