CVE-2024-58295: ElkArte Forum 1.1.9 Authenticated Remote Code Execution via Theme Upload
ElkArte Forum 1.1.9 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the theme installation process. Attackers can upload a ZIP archive with a PHP file containing system commands, which can then be executed by accessing the uploaded file in the theme directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-58295?
CVE-2024-58295 is rated as a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2024-58295?
To fix CVE-2024-58295, upgrade to the latest version of ElkArte Forum that patches this vulnerability.
Who is affected by CVE-2024-58295?
The vulnerability CVE-2024-58295 affects authenticated administrators of ElkArte Forum 1.1.9 who can upload files during theme installation.
What type of vulnerability is CVE-2024-58295?
CVE-2024-58295 is classified as a remote code execution vulnerability.
Can an attacker exploit CVE-2024-58295 without authentication?
No, an attacker must be an authenticated administrator to exploit CVE-2024-58295.