CVE-2024-40645: FOG Authenticated File Upload RCE
FOG is a cloning/imaging/rescue suite/inventory management system. An improperly restricted file upload feature allows authenticated users to execute arbitrary code on the fogproject server. The Rebranding feature has a check on the client banner image requiring it to be 650 pixels wide and 120 pixels high. Apart from that, there are no checks on things like file extensions. This can be abused by appending a PHP webshell to the end of the image and changing the extension to anything the PHP web server will parse. This vulnerability is fixed in 1.5.10.41.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-40645?
CVE-2024-40645 is categorized as a high severity vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2024-40645?
To fix CVE-2024-40645, update Fogproject to version 1.5.10.41 or later where the file upload restrictions have been properly implemented.
Who is impacted by CVE-2024-40645?
Authenticated users of Fogproject versions prior to 1.5.10.41 are impacted by CVE-2024-40645.
What type of vulnerability is CVE-2024-40645?
CVE-2024-40645 is an arbitrary code execution vulnerability caused by improperly restricted file upload functionality.
When was CVE-2024-40645 reported?
CVE-2024-40645 was reported as part of ongoing security analysis and is addressed in the latest releases of Fogproject.