Code Injection Vulnerability in Flute CMS Notification Handler
CVE-2024-6947
Key Information:
Badges
What is CVE-2024-6947?
A significant security vulnerability has been discovered in Flute CMS version 0.2.2.4-alpha, specifically within the Notification Handler component's replaceContent function located in app/Core/Support/ContentParser.php. This vulnerability opens the door for remote code injection, allowing malicious actors to manipulate the content processing function and potentially execute arbitrary code on affected systems. Given that this flaw has been publicly disclosed, it poses an urgent risk to all installations of the affected version. Administrators are strongly advised to apply security patches or implement mitigations to prevent exploitation.
Affected Version(s)
CMS 0.2.2.4-alpha
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved