First published: Fri Jul 12 2024(Updated: )
An arbitrary file upload vulnerability in the component /admin/cmsWebFile/doUpload of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
sanluan PublicCMS | <=4.0.202302.e |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-40545 has been classified with a high severity rating due to its potential for arbitrary file upload and code execution.
To fix CVE-2024-40545, upgrade to a version of PublicCMS later than 4.0.202302.e that addresses this vulnerability.
CVE-2024-40545 affects PublicCMS v4.0.202302.e and earlier versions.
CVE-2024-40545 allows attackers to execute arbitrary code by uploading a crafted file via the vulnerable upload component.
Detailed information about CVE-2024-40545 can be found in the official issue tracker for PublicCMS.