CVE-2024-33752: Malicious File Upload
Published May 6, 2024
·Updated
An arbitrary file upload vulnerability exists in emlog pro 2.3.0 and pro 2.3.2 at admin/views/plugin.php that could be exploited by a remote attacker to submit a special request to upload a malicious file to execute arbitrary code.
Affected Software
3 affected components
Emlog pro>=2.3.0<=2.3.2
Emlog emlog=2.3.0
Emlog emlog=2.3.2
Event History
May 6, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-33752?
CVE-2024-33752 is rated as a high-severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2024-33752?
To fix CVE-2024-33752, update emlog pro to version 2.3.3 or later where the vulnerability has been patched.
3
What versions of emlog pro are affected by CVE-2024-33752?
CVE-2024-33752 affects emlog pro versions 2.3.0 and 2.3.2.
4
Can CVE-2024-33752 be exploited remotely?
Yes, CVE-2024-33752 can be exploited remotely by attackers through malicious file uploads.
5
What type of vulnerability is CVE-2024-33752?
CVE-2024-33752 is an arbitrary file upload vulnerability, allowing unauthorized file uploads that could lead to code execution.