CVE-2024-40545

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-40545
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-40545.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-40545
Published
2024-07-12T16:15:05Z
Modified
2025-02-19T03:38:20.755336Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

An arbitrary file upload vulnerability in the component /admin/cmsWebFile/doUpload of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.

References

Affected packages

Git / github.com/sanluan/publiccms

Affected ranges

Type
GIT
Repo
https://github.com/sanluan/publiccms
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

Other

V2016

V4.*

V4.0.180707
V4.0.181024
V4.0.190312
V4.0.202004
V4.0.202011
V4.0.202107
V4.0.202107.b
V4.0.202107.c
V4.0.202107.d
V4.0.202107.f
V4.0.202204.a
V4.0.202204.b
V4.0.202204.c
V4.0.202204.d
V4.0.202302.a
V4.0.202302.b
V4.0.202302.c
V4.0.202302.d
V4.0.202302.e
V4.0.202302.f