First published: Tue Jul 09 2024(Updated: )
Unrestricted Upload of File with Dangerous Type vulnerability in Andy Moyle Church Admin allows Upload a Web Shell to a Web Server.This issue affects Church Admin: from n/a through 4.4.6.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Andy Moyle Church Admin | <=4.4.6 | |
WordPress Church Admin | <=4.4.6 |
Update to 4.4.7 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-37418 is considered a high-severity vulnerability due to its potential for unauthorized file uploads leading to remote code execution.
To fix CVE-2024-37418, users should update to version 4.4.7 or later of the Church Admin software to mitigate the file upload vulnerability.
CVE-2024-37418 affects Andy Moyle Church Admin versions up to 4.4.6 and the WordPress Church Admin plugin versions up to 4.4.6.
The impact of CVE-2024-37418 includes the risk of an attacker uploading malicious files, such as web shells, which can compromise the web server.
While the best solution is to update, temporary workarounds may involve restricting file upload types and validating uploaded files but are not foolproof.