First published: Tue Nov 26 2024(Updated: )
An authenticated arbitrary file upload vulnerability in the Documents module of SPIP v4.3.3 allows attackers to execute arbitrary code via uploading a crafted PDF file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Spip |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-53619 is considered a high severity vulnerability due to the potential for arbitrary code execution through file uploads.
To fix CVE-2024-53619, update SPIP to the latest version that addresses this vulnerability and restrict file upload types.
CVE-2024-53619 can facilitate remote code execution attacks by allowing attackers to upload and execute malicious files.
The vulnerability affects users of SPIP version 4.3.3 and potentially earlier versions of the Documents module.
No, CVE-2024-53619 requires authentication to exploit, as it targets file uploads within the authenticated user context.