CVE-2024-22724: Code Injection
Published Mar 21, 2024
·Updated
An issue was discovered in osCommerce v4, allows local attackers to bypass file upload restrictions and execute arbitrary code via administrator profile photo upload feature.
Affected Software
2 affected components
osCommerce oscommerce
osCommerce oscommerce=4.0
Event History
Mar 21, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-22724?
CVE-2024-22724 is considered a critical vulnerability due to its potential to allow arbitrary code execution.
2
How do I fix CVE-2024-22724?
To fix CVE-2024-22724, you should update to the latest version of osCommerce that addresses this vulnerability.
3
Who is affected by CVE-2024-22724?
CVE-2024-22724 affects installations of osCommerce v4 that have not implemented proper file upload restrictions.
4
What type of attack does CVE-2024-22724 enable?
CVE-2024-22724 enables local attackers to bypass file upload restrictions in the administrator profile photo upload feature.
5
What is osCommerce's response to CVE-2024-22724?
OsCommerce has acknowledged CVE-2024-22724 and is actively working on a patch to resolve the vulnerability.