Code Injection Vulnerability in Flute CMS Notification Handler
CVE-2024-6947
Key Information:
Badges
What is CVE-2024-6947?
A significant security vulnerability has been discovered in Flute CMS version 0.2.2.4-alpha, specifically within the Notification Handler component's replaceContent function located in app/Core/Support/ContentParser.php. This vulnerability opens the door for remote code injection, allowing malicious actors to manipulate the content processing function and potentially execute arbitrary code on affected systems. Given that this flaw has been publicly disclosed, it poses an urgent risk to all installations of the affected version. Administrators are strongly advised to apply security patches or implement mitigations to prevent exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
CMS 0.2.2.4-alpha
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
