A vulnerability, which was classified as critical, was found in PHPVibe 11.0.46. Affected is an unknown function of the file /app/uploading/upload-mp3.php of the component Media Upload Page. The manipulation of the argument file leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-268824. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
History

Mon, 16 Sep 2024 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Phpvibe
Phpvibe phpvibe
CPEs cpe:2.3:a:phpvibe:phpvibe:11.0.46:*:*:*:*:*:*:*
Vendors & Products Phpvibe
Phpvibe phpvibe

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2024-06-17T23:31:03.508Z

Updated: 2024-09-03T17:42:07.637Z

Reserved: 2024-06-17T17:12:56.547Z

Link: CVE-2024-6083

cve-icon Vulnrichment

Updated: 2024-08-01T21:25:03.307Z

cve-icon NVD

Status : Analyzed

Published: 2024-06-18T00:15:09.853

Modified: 2024-09-16T13:21:53.467

Link: CVE-2024-6083

cve-icon Redhat

No data.