Remote Attacker Can Execute Arbitrary Code via Publish.php Component
CVE-2024-31823
8.8HIGH
Key Information:
- Vendor
- CVE Published:
- 29 April 2024
What is CVE-2024-31823?
A vulnerability exists in the Ecommerce-CodeIgniter-Bootstrap framework, allowing remote attackers to execute arbitrary code. This flaw arises from a weakness in the 'removeSecondaryImage' method in the Publish.php component, which can be exploited by sending crafted requests. This issue highlights the importance of secure coding practices and timely updates.
