A vulnerability was found in Flute CMS 0.2.2.4-alpha. It has been classified as critical. This affects an unknown part of the file app/Core/Http/Controllers/Profile/ImagesController.php of the component Avatar Upload Page. The manipulation of the argument avatar leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272067.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-47931 A vulnerability was found in Flute CMS 0.2.2.4-alpha. It has been classified as critical. This affects an unknown part of the file app/Core/Http/Controllers/Profile/ImagesController.php of the component Avatar Upload Page. The manipulation of the argument avatar leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272067.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 05 Sep 2024 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Flute-cms
Flute-cms flute
CPEs cpe:2.3:a:flute-cms:flute:0.2.2.4:alpha:*:*:*:*:*:*
Vendors & Products Flute-cms
Flute-cms flute

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2024-08-01T21:45:38.371Z

Reserved: 2024-07-20T10:06:03.134Z

Link: CVE-2024-6945

cve-icon Vulnrichment

Updated: 2024-08-01T21:45:38.371Z

cve-icon NVD

Status : Modified

Published: 2024-07-21T08:15:07.140

Modified: 2024-11-21T09:50:36.563

Link: CVE-2024-6945

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.