CVE-2024-37418: WordPress Church Admin plugin <= 4.4.6 - Arbitrary File Upload vulnerability
Unrestricted Upload of File with Dangerous Type vulnerability in andymoyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.4.6.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37418?
CVE-2024-37418 is considered a high-severity vulnerability due to its potential for unauthorized file uploads leading to remote code execution.
How do I fix CVE-2024-37418?
To fix CVE-2024-37418, users should update to version 4.4.7 or later of the Church Admin software to mitigate the file upload vulnerability.
What software is affected by CVE-2024-37418?
CVE-2024-37418 affects Andy Moyle Church Admin versions up to 4.4.6 and the WordPress Church Admin plugin versions up to 4.4.6.
What is the impact of CVE-2024-37418?
The impact of CVE-2024-37418 includes the risk of an attacker uploading malicious files, such as web shells, which can compromise the web server.
Is there a workaround for CVE-2024-37418?
While the best solution is to update, temporary workarounds may involve restricting file upload types and validating uploaded files but are not foolproof.