First published: Fri Jul 12 2024(Updated: )
An arbitrary file upload vulnerability in the component /admin/cmsTemplate/doUpload of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
sanluan PublicCMS | <=4.0.202302.e |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-40551 has been rated as a critical vulnerability due to its ability to allow arbitrary code execution.
To fix CVE-2024-40551, update PublicCMS to version 4.0.202302.f or later, which addresses the arbitrary file upload vulnerability.
The impacts of CVE-2024-40551 include unauthorized access, data compromise, and potential server takeover due to arbitrary code execution.
CVE-2024-40551 affects all versions of PublicCMS up to and including 4.0.202302.e.
CVE-2024-40551 allows attackers to exploit the system by uploading a specially crafted file that can execute arbitrary code on the server.