Arbitrary File Upload Vulnerability in Lylme Spage
CVE-2024-34982
9.8CRITICAL
What is CVE-2024-34982?
This vulnerability in the Lylme Spage application arises from an improper file handling mechanism in the component responsible for processing file uploads. Specifically, the vulnerability lies in the /include/file.php script, which fails to adequately validate the content and type of files being uploaded. As a consequence, this oversight allows attackers to upload maliciously crafted files that can execute arbitrary code on the server. This exploitation can lead to compromised systems and potential exposure of sensitive data, highlighting the necessity for stringent file validation mechanisms.