Unrestricted File Upload Vulnerability Affects Gallerio
CVE-2024-52400
9.9CRITICAL
What is CVE-2024-52400?
An arbitrary file upload vulnerability exists in Gallerio developed by Subhasis Laha, which permits the upload of files with dangerous types. This flaw allows attackers to upload a web shell to the server, potentially leading to remote code execution. The vulnerability affects all versions of Gallerio up to 1.01 and raises significant security concerns for users, as it opens up pathways for unauthorized access and manipulation of server contents.
Affected Version(s)
Gallerio <= 1.01