CVE-2024-40548: Malicious File Upload
Published Jul 12, 2024
·Updated
An arbitrary file upload vulnerability in the component /admin/cmsTemplate/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.
Affected Software
1 affected component
PublicCMS publiccms<=4.0.202302.e
Event History
Jul 12, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-40548?
CVE-2024-40548 is classified as a critical severity vulnerability due to its potential for arbitrary code execution.
2
How do I fix CVE-2024-40548?
To fix CVE-2024-40548, update PublicCMS to version 4.0.202302.f or later as it includes patches for this vulnerability.
3
What type of attack is possible with CVE-2024-40548?
CVE-2024-40548 allows attackers to perform arbitrary file uploads, potentially leading to remote code execution.
4
Who is affected by CVE-2024-40548?
Any user of PublicCMS versions up to and including 4.0.202302.e is affected by CVE-2024-40548.
5
What component is vulnerable in CVE-2024-40548?
CVE-2024-40548 affects the /admin/cmsTemplate/save component of PublicCMS.