CVE-2024-24551 Vulnerability Details
/
/
/
CVE-2024-24551 Metadata Quick Info
CVE Published: 24/06/2024 |
CVE Updated: 01/08/2024 |
CVE Year: 2024
Source: NCSC.ch |
Vendor: Bludit |
Product: Bludit
Status : PUBLISHED
CVE-2024-24551 Description
A security vulnerability has been identified in Bludit, allowing authenticated attackers to execute arbitrary code through the Image API. This vulnerability arises from improper handling of file uploads, enabling malicious actors to upload and execute PHP files.
Metrics
CVSS Version: 3.1 |
Base Score: n/a
Vector: n/a
l➤ Exploitability Metrics:
Attack Vector (AV)*
Attack Complexity (AC)*
Privileges Required (PR)*
User Interaction (UI)*
Scope (S)*
l➤ Impact Metrics:
Confidentiality Impact (C)*
Integrity Impact (I)*
Availability Impact (A)*
Weakness Enumeration (CWE)
CWE-ID: CWE-77
CWE Name: CWE-77 Improper Neutralization of Special Elements used in a Command (
Command Injection
)
Source: Bludit
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID: CAPEC-650
CAPEC Description: CAPEC-650 Upload a Web Shell to a Web Server
Source: NVD (National Vulnerability Database).