Insecure File Upload in xbtitFM 4.1.18 by xbtit
CVE-2024-58313
Key Information:
Badges
What is CVE-2024-58313?
xbtitFM 4.1.18 contains an insecure file upload vulnerability that allows authenticated administrators to upload arbitrary PHP files through the file_hosting feature. Attackers can exploit this by bypassing file type restrictions, using techniques such as modifying the Content-Type header to 'image/gif', appending GIF89a magic bytes, and employing alternate PHP tags. This could potentially lead to remote code execution, allowing the attacker to execute system commands on the server.
Affected Version(s)
xbtitFM 4.1.18
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
