CVE-2024-40552: Code Injection
Published Jul 12, 2024
·Updated
PublicCMS v4.0.202302.e was discovered to contain a remote commande execution (RCE) vulnerability via the cmdarray parameter at /site/ScriptComponent.java.
Affected Software
1 affected component
PublicCMS publiccms<=4.0.202302.e
Event History
Jul 12, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-40552?
CVE-2024-40552 has been classified as a critical severity vulnerability due to its remote code execution capability.
2
How do I fix CVE-2024-40552?
To fix CVE-2024-40552, upgrade PublicCMS to a version above 4.0.202302.e where the vulnerability has been addressed.
3
What software is affected by CVE-2024-40552?
CVE-2024-40552 affects PublicCMS versions up to and including 4.0.202302.e.
4
What type of vulnerability is CVE-2024-40552?
CVE-2024-40552 is a remote code execution (RCE) vulnerability.
5
How can attackers exploit CVE-2024-40552?
Attackers can exploit CVE-2024-40552 by sending crafted requests containing malicious commands to the cmdarray parameter.