CVE-2024-58279

Source
https://cve.org/CVERecord?id=CVE-2024-58279
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-58279.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-58279
Published
2025-12-10T21:12:47Z
Modified
2026-08-12T03:51:19Z
Severity
  • 8.6 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
appRain CMF 4.0.5 Authenticated Remote Code Execution via Filemanager Upload
Details

appRain CMF 4.0.5 contains an authenticated remote code execution vulnerability that allows administrative users to upload malicious PHP files through the filemanager upload endpoint. Attackers can leverage authenticated access to generate a web shell with command execution capabilities by uploading a crafted PHP file to the site's uploads directory.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-434"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/58xxx/CVE-2024-58279.json"
}
References

Affected packages

Git / github.com/apprain/apprain

Affected ranges

Type
GIT
Repo
https://github.com/apprain/apprain
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:apprain:apprain:4.0.5:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "4.0.5"
        },
        {
            "last_affected": "4.0.5"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_STRING"
    ]
}

Affected versions

4.*
4.0.5
v4.*
v4.0.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-58279.json"