CVE-2024-40546: Malicious File Upload
Published Jul 12, 2024
·Updated
An arbitrary file upload vulnerability in the component /admin/cmsWebFile/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.
Affected Software
1 affected component
PublicCMS publiccms<=4.0.202302.e
Event History
Jul 12, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-40546?
CVE-2024-40546 is classified as a critical vulnerability due to its potential to allow arbitrary code execution.
2
How do I fix CVE-2024-40546?
To fix CVE-2024-40546, upgrade PublicCMS to version 4.0.202302.f or later, where the vulnerability has been addressed.
3
What systems are affected by CVE-2024-40546?
CVE-2024-40546 affects all versions of PublicCMS up to and including 4.0.202302.e.
4
What type of attack can exploit CVE-2024-40546?
CVE-2024-40546 can be exploited through arbitrary file upload attacks that allow execution of malicious files.
5
Is there a workaround for CVE-2024-40546?
Currently, there are no known effective workarounds for CVE-2024-40546; upgrading is the recommended action.