CVE-2024-8296: FeehiCMS index.php insert unrestricted upload
A vulnerability was found in FeehiCMS up to 2.1.1 and classified as critical. This issue affects the function insert of the file /admin/index.php?r=user%2Fcreate. The manipulation of the argument User[avatar] leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8296?
CVE-2024-8296 is classified as a critical vulnerability.
How do I fix CVE-2024-8296?
To fix CVE-2024-8296, it is recommended to update FeehiCMS to a version higher than 2.1.1.
What component is affected by CVE-2024-8296?
CVE-2024-8296 affects the insert function in the file /admin/index.php specifically targeting User[avatar].
Can CVE-2024-8296 be exploited remotely?
Yes, CVE-2024-8296 can be exploited remotely, allowing attackers to initiate the attack without physical access.
What type of vulnerability is CVE-2024-8296?
CVE-2024-8296 is an unrestricted file upload vulnerability that compromises the security of the application.