First published: Thu Jul 25 2024(Updated: )
An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
QloApps | =1.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-40318 is classified as a critical vulnerability due to its potential for remote code execution.
To fix CVE-2024-40318, upgrade Webkul Qloapps to the latest version that addresses this vulnerability.
CVE-2024-40318 specifically affects Webkul Qloapps version 1.6.0.
CVE-2024-40318 can be exploited by attackers to upload arbitrary files which may lead to arbitrary code execution.
Yes, a patch is available in the latest version of Webkul Qloapps to mitigate CVE-2024-40318.