Arbitrary File Upload Vulnerability in Lektor Static CMS
CVE-2024-28335

9.1CRITICAL

Key Information:

Vendor

Lektor

Vendor
CVE Published:
27 March 2024

What is CVE-2024-28335?

A security issue has been identified in Lektor Static CMS versions prior to 3.3.11, which does not properly sanitize database path traversal. This vulnerability enables potential attackers to execute arbitrary shell commands. The attack surface is particularly pronounced when a user’s web browser visits an untrusted site that uses JavaScript to send requests to the localhost port 5000, and this occurs while running the 'lektor server' command on the same machine. Maliciously crafted files uploaded to the templates directory could exploit this weakness and lead to severe security implications.

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.