CVE-2024-24550: Bludit - Remote Code Execution (RCE) through File API
A security vulnerability has been identified in Bludit, allowing attackers with knowledge of the API token to upload arbitrary files through the File API which leads to arbitrary code execution on the server. This vulnerability arises from improper handling of file uploads, enabling malicious actors to upload and execute PHP files.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24550?
CVE-2024-24550 is rated as a high-severity vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2024-24550?
To fix CVE-2024-24550, ensure that the Bludit software is updated to the latest version that patched this vulnerability.
What types of attacks are possible with CVE-2024-24550?
CVE-2024-24550 allows attackers to upload arbitrary files, leading to potential remote code execution on the server.
Who is affected by CVE-2024-24550?
CVE-2024-24550 affects all versions of Bludit that improperly handle file uploads.
Is there a workaround for CVE-2024-24550 before applying a patch?
Currently, there are no recommended workarounds for CVE-2024-24550; updating the software is the best mitigation strategy.