Unrestricted File Upload Vulnerability Discovered in Flute CMS 0.2.2.4-alpha
CVE-2024-6945
Key Information:
Badges
What is CVE-2024-6945?
A vulnerability identified in Flute CMS version 0.2.2.4-alpha impacts the Avatar Upload Page, specifically within the ImagesController.php file. The vulnerably allows attackers to manipulate the avatar upload functionality to execute unrestricted file uploads. This weakness can be exploited remotely, giving malicious entities the ability to upload unauthorized files, potentially leading to further system exploitation. The vulnerability has been publicly disclosed and poses a significant risk to systems utilizing Flute CMS. Comprehensive measures should be taken to mitigate exposure to this vulnerability.
Affected Version(s)
CMS 0.2.2.4-alpha
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved