CVE-2024-40400: Malicious File Upload
Published Jul 19, 2024
·Updated
An arbitrary file upload vulnerability in the image upload function of Automad v2.0.0 allows attackers to execute arbitrary code via a crafted file.
Affected Software
6 affected componentsFixes available
composer/automad/automad<2.0.0-alpha.5
2.0.0-alpha.5
Automad Automad<=1.10.9
Automad Automad=2.0.0-alpha1
Automad Automad=2.0.0-alpha2
Automad Automad=2.0.0-alpha3
Automad Automad=2.0.0-alpha4
Event History
Jul 19, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·09:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-40400?
CVE-2024-40400 is classified as a high severity vulnerability due to its potential for arbitrary code execution.
2
How do I fix CVE-2024-40400?
To mitigate CVE-2024-40400, upgrade to Automad version 2.0.0-alpha.5 or later.
3
What type of vulnerability is CVE-2024-40400?
CVE-2024-40400 is an arbitrary file upload vulnerability found in the image upload function of Automad.
4
Can CVE-2024-40400 be exploited remotely?
Yes, CVE-2024-40400 can be exploited remotely if an attacker uploads a crafted file to the application.
5
Which versions of Automad are affected by CVE-2024-40400?
Automad version 2.0.0 and any prior versions are affected by CVE-2024-40400.