First published: Fri Jul 12 2024(Updated: )
An arbitrary file upload vulnerability in the component /admin/cmsWebFile/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
sanluan PublicCMS | <=4.0.202302.e |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-40546 is classified as a critical vulnerability due to its potential to allow arbitrary code execution.
To fix CVE-2024-40546, upgrade PublicCMS to version 4.0.202302.f or later, where the vulnerability has been addressed.
CVE-2024-40546 affects all versions of PublicCMS up to and including 4.0.202302.e.
CVE-2024-40546 can be exploited through arbitrary file upload attacks that allow execution of malicious files.
Currently, there are no known effective workarounds for CVE-2024-40546; upgrading is the recommended action.