NONE · 0

CVE-2024-58295

ElkArte Forum 1.1.9 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the theme installation process. Attackers can upload a...

Vulnerability Description

ElkArte Forum 1.1.9 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the theme installation process. Attackers can upload a ZIP archive with a PHP file containing system commands, which can then be executed by accessing the uploaded file in the theme directory.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-58295?

CVE-2024-58295 is a documented vulnerability. ElkArte Forum 1.1.9 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the theme installation process. Attackers can upload a...

How severe is CVE-2024-58295?

CVSS scoring is not yet available for CVE-2024-58295. Check NVD for updates.

Is there a patch for CVE-2024-58295?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.