First published: Tue Jan 21 2025(Updated: )
Unrestricted Upload of File with Dangerous Type vulnerability in NotFound Fancy Product Designer. This issue affects Fancy Product Designer: from n/a through 6.4.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fancy Product Designer | <=6.4.3 | |
Fancy Product Designer | <=6.4.3 |
No patched version is provided by the vendor. No reply from the vendor.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-51919 has a high severity due to the potential for unrestricted file uploads leading to arbitrary code execution.
To fix CVE-2024-51919, update the Fancy Product Designer plugin to version 6.4.4 or newer.
CVE-2024-51919 affects Fancy Product Designer versions up to and including 6.4.3 and the WordPress Fancy Product Designer plugin versions up to and including 6.4.3.
Yes, CVE-2024-51919 can be exploited remotely without authentication, allowing attackers to upload malicious files.
In the context of CVE-2024-51919, dangerous file types include executable scripts and files with extensions that can execute code on the server.