CVE-2024-40549: Malicious File Upload
Published Jul 12, 2024
·Updated
An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlace of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.
Affected Software
1 affected component
PublicCMS PublicCMS<=4.0.202302.e
Event History
Jul 12, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-40549?
CVE-2024-40549 is categorized as a high severity vulnerability due to its potential to allow arbitrary code execution.
2
How do I fix CVE-2024-40549?
To fix CVE-2024-40549, upgrade PublicCMS to version 4.0.202302.e or apply any security patches provided by the vendor.
3
What components are affected by CVE-2024-40549?
CVE-2024-40549 affects the /admin/cmsTemplate/savePlace component of PublicCMS v4.0.202302.e.
4
Can CVE-2024-40549 be exploited remotely?
Yes, CVE-2024-40549 can be exploited remotely by uploading a crafted file to the affected component.
5
What are the consequences of exploiting CVE-2024-40549?
Exploiting CVE-2024-40549 can lead to unauthorized code execution on the server, potentially compromising the system.