Code Injection Vulnerability in Flute CMS
CVE-2024-6946

8.8HIGH

Key Information:

Vendor

Flute

Status
Vendor
CVE Published:
21 July 2024

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2024-6946?

A critical vulnerability exists in Flute CMS version 0.2.2.4-alpha that allows an attacker to exploit the administrative functionality of the application. Specifically, the vulnerability is rooted in the manipulation of arguments within the /admin/pages/list file, leading to potential code injection attacks. Since the exploit can be initiated remotely, this poses a significant risk to web applications utilizing the Flute CMS framework, allowing unauthorized execution of commands and compromising system integrity. This vulnerability has been disclosed publicly and may be actively exploited by attackers, underscoring the urgency for affected users to implement necessary security measures and updates.

Affected Version(s)

CMS 0.2.2.4-alpha

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dee.Mirage (VulDB User)
.