Arbitrary File Upload Vulnerability in Lylme Spage
CVE-2024-34982

9.8CRITICAL

Key Information:

Vendor

Lylme

Vendor
CVE Published:
17 May 2024

What is CVE-2024-34982?

This vulnerability in the Lylme Spage application arises from an improper file handling mechanism in the component responsible for processing file uploads. Specifically, the vulnerability lies in the /include/file.php script, which fails to adequately validate the content and type of files being uploaded. As a consequence, this oversight allows attackers to upload maliciously crafted files that can execute arbitrary code on the server. This exploitation can lead to compromised systems and potential exposure of sensitive data, highlighting the necessity for stringent file validation mechanisms.

References

EPSS Score

71% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.
CVE-2024-34982 : Arbitrary File Upload Vulnerability in Lylme Spage