Vulnerability Description
SKINsoft S-Museum 7.02.3 allows Unrestricted File Upload via the Add Media function. Unlike in CVE-2024-25801, the attack payload is the file content.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Skinsoft | S-Museum | 7.02.3 |
Related Weaknesses (CWE)
References
- https://shrouded-trowel-50c.notion.site/S-Museum-Version-7-02-3-Unrestricted-FilBroken Link
- https://shrouded-trowel-50c.notion.site/S-Museum-Version-7-02-3-Unrestricted-FilBroken Link
FAQ
What is CVE-2024-25802?
CVE-2024-25802 is a vulnerability with a CVSS score of 9.8 (CRITICAL). SKINsoft S-Museum 7.02.3 allows Unrestricted File Upload via the Add Media function. Unlike in CVE-2024-25801, the attack payload is the file content.
How severe is CVE-2024-25802?
CVE-2024-25802 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-25802?
Check the references section above for vendor advisories and patch information. Affected products include: Skinsoft S-Museum.