First published: Wed Oct 23 2024(Updated: )
A vulnerability was found in ZZCMS 2023 and classified as critical. This issue affects some unknown processing of the file 3/Ebak5.1/upload/ChangeTable.php. The manipulation of the argument savefilename leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
ZZCMS | =2023 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-10292 is classified as critical due to its potential for remote exploitation.
To fix CVE-2024-10292, ensure that file uploads are strictly validated and implement proper restrictions on the 'savefilename' argument.
CVE-2024-10292 affects ZZCMS version 2023.
Yes, CVE-2024-10292 can be exploited remotely through the vulnerable file upload functionality.
The impact of CVE-2024-10292 includes the potential for unauthorized file uploads which may compromise the system.