CVE-2024-24551: Bludit - Remote Code Execution (RCE) through Image API
A security vulnerability has been identified in Bludit, allowing authenticated attackers to execute arbitrary code through the Image API. This vulnerability arises from improper handling of file uploads, enabling malicious actors to upload and execute PHP files.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24551?
CVE-2024-24551 is considered a high severity vulnerability due to the potential for authenticated attackers to execute arbitrary code.
How do I fix CVE-2024-24551?
To fix CVE-2024-24551, update Bludit to the latest version that addresses the file upload handling issue.
Who is affected by CVE-2024-24551?
CVE-2024-24551 affects installations of Bludit that allow file uploads via the Image API.
What can attackers do with CVE-2024-24551?
Attackers can upload and execute malicious PHP files on the server due to improper file handling in Bludit's Image API.
Is there a workaround for CVE-2024-24551?
A temporary workaround for CVE-2024-24551 includes disabling file uploads until the software is updated.