CVE-2024-55529: Code Injection
Published Jan 6, 2025
·Updated
Z-BlogPHP 1.7.3 is vulnerable to arbitrary code execution via \zbusers\theme\shell\template.
Affected Software
2 affected components
Z-BlogPHP Z-BlogPHP
ZblogCN Z-blogphp=1.7.3
Event History
Jan 6, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-55529?
CVE-2024-55529 is considered a critical vulnerability that allows arbitrary code execution.
2
How do I fix CVE-2024-55529?
To fix CVE-2024-55529, upgrade Z-BlogPHP to the latest version that addresses this vulnerability.
3
What are the potential impacts of CVE-2024-55529?
The potential impacts of CVE-2024-55529 include unauthorized remote code execution, leading to full system compromise.
4
Who is affected by CVE-2024-55529?
CVE-2024-55529 affects users of Z-BlogPHP version 1.7.3.
5
What is the attack vector for CVE-2024-55529?
The attack vector for CVE-2024-55529 involves exploiting vulnerabilities in the template handling feature within Z-BlogPHP.