Vulnerability Description
A vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in ‘/media/api’ parameter via post request. An attacker could upload files to the server, compromising the entire infrastructure.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Agentejo | Cockpit | 0.5.5 |
Related Weaknesses (CWE)
References
- https://www.incibe.es/en/incibe-cert/notices/aviso/unrestricted-upload-file-dangThird Party Advisory
- https://www.incibe.es/en/incibe-cert/notices/aviso/unrestricted-upload-file-dangThird Party Advisory
FAQ
What is CVE-2024-4825?
CVE-2024-4825 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in ‘/media/api’ parameter via post request. An attacker could upload files to the server, c...
How severe is CVE-2024-4825?
CVE-2024-4825 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-4825?
Check the references section above for vendor advisories and patch information. Affected products include: Agentejo Cockpit.