CVE-2024-41454: Malicious File Upload
An arbitrary file upload vulnerability in the UI login page logo upload function of Process Maker pm4core-docker 4.1.21-RC7 allows attackers to execute arbitrary code via uploading a crafted PHP or HTML file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41454?
CVE-2024-41454 has a high severity rating due to its potential to allow arbitrary code execution.
How do I fix CVE-2024-41454?
To fix CVE-2024-41454, update Process Maker pm4core-docker to the latest version that has patched this vulnerability.
What type of vulnerability is CVE-2024-41454?
CVE-2024-41454 is an arbitrary file upload vulnerability that can be exploited through the UI login page logo upload function.
Can CVE-2024-41454 be exploited remotely?
Yes, CVE-2024-41454 can be exploited remotely by an attacker who can access the login page.
What impact does CVE-2024-41454 have on affected systems?
The impact of CVE-2024-41454 includes the potential for attackers to execute arbitrary code, compromising the integrity and confidentiality of the affected system.