CVE-2024-58295
⚪ Do wiadomości
Wykonanie zdalnego kodu w ElkArte Forum umożliwia administratorom przesyłanie złośliwych plików PHP.
CVSS
0.0
EPSS
0.6%
Exploit
none
Vendor
Opis źródłowy (NVD)
ElkArte Forum 1.1.9 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the theme installation process. Attackers can upload a ZIP archive with a PHP file containing system commands, which can then be executed by accessing the uploaded file in the theme directory.
rce
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 0.0 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.6% |
| Opublikowano (NVD) | 2025-12-11 22:15:50 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-02 00:10:00 UTC |
Referencje
- https://github.com/elkarte/Elkarte/releases/download/v1.1.9/ElkArte_v1-1-9_install.zip ([email protected])
- https://www.elkarte.net/ ([email protected])
- https://www.exploit-db.com/exploits/52026 ([email protected])
- https://www.vulncheck.com/advisories/elkarte-forum-authenticated-remote-code-execution-via-theme-upload ([email protected])