CVE-2024-4825: Unrestricted Upload of File with Dangerous Type vulnerability on Cockpit CMS from Agentejo
A vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in ‘/media/api’ parameter via post request. An attacker could upload files to the server, compromising the entire infrastructure.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/cockpit-hq/cockpitto a version that resolves this vulnerability.Fixed in 2.7.0 - Upgrade
Upgrade
Agentejo Cockpit CMSto a version that resolves this vulnerability.Fixed in 2.7.0
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4825?
CVE-2024-4825 is considered a critical vulnerability due to its potential for arbitrary file upload which could compromise server infrastructure.
How do I fix CVE-2024-4825?
To mitigate CVE-2024-4825, upgrade Agentejo Cockpit CMS to version 2.7.0 or higher.
What is the potential impact of CVE-2024-4825?
The potential impact of CVE-2024-4825 includes unauthorized access, data exposure, and full system compromise from malicious file uploads.
Which versions of Cockpit CMS are affected by CVE-2024-4825?
CVE-2024-4825 affects Agentejo Cockpit CMS versions prior to 2.7.0.
Is there a workaround for CVE-2024-4825 if I cannot upgrade?
Currently, no reliable workaround is recommended for CVE-2024-4825, so upgrading is advised.