CVE-2024-40545: Malicious File Upload
Published Jul 12, 2024
·Updated
An arbitrary file upload vulnerability in the component /admin/cmsWebFile/doUpload of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.
Affected Software
1 affected component
PublicCMS publiccms<=4.0.202302.e
Event History
Jul 12, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-40545?
CVE-2024-40545 has been classified with a high severity rating due to its potential for arbitrary file upload and code execution.
2
How do I fix CVE-2024-40545?
To fix CVE-2024-40545, upgrade to a version of PublicCMS later than 4.0.202302.e that addresses this vulnerability.
3
What systems are affected by CVE-2024-40545?
CVE-2024-40545 affects PublicCMS v4.0.202302.e and earlier versions.
4
What type of attack can be executed through CVE-2024-40545?
CVE-2024-40545 allows attackers to execute arbitrary code by uploading a crafted file via the vulnerable upload component.
5
Where can I find more details about CVE-2024-40545?
Detailed information about CVE-2024-40545 can be found in the official issue tracker for PublicCMS.