First published: Mon Nov 04 2024(Updated: )
Unrestricted Upload of File with Dangerous Type vulnerability in mahlamusa Multi Purpose Mail Form allows Upload a Web Shell to a Web Server.This issue affects Multi Purpose Mail Form: from n/a through 1.0.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lindeni Multi Purpose Mail Form | <=1.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-50526 is considered critical due to the potential for unrestricted file uploads leading to the execution of malicious web shells.
To fix CVE-2024-50526, update the Multi Purpose Mail Form plugin to a version higher than 1.0.2 to mitigate the vulnerability.
CVE-2024-50526 affects all versions of the Multi Purpose Mail Form plugin up to and including 1.0.2.
Yes, CVE-2024-50526 can allow attackers to upload a web shell which can be used to execute arbitrary code on the server.
No, user authentication is not sufficient to protect against CVE-2024-50526 as the vulnerability specifically allows for unrestricted file uploads regardless of user permissions.