CVE-2024-58295

⚪ Do wiadomości

Wykonanie zdalnego kodu w ElkArte Forum umożliwia administratorom przesyłanie złośliwych plików PHP.

CVSS
0.0
EPSS
0.6%
Exploit
none
Vendor
Opis źródłowy (NVD)

ElkArte Forum 1.1.9 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the theme installation process. Attackers can upload a ZIP archive with a PHP file containing system commands, which can then be executed by accessing the uploaded file in the theme directory.

rce Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS0.0
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.6%
Opublikowano (NVD)2025-12-11 22:15:50 UTC
Ostatnia modyfikacja (NVD)2026-10-02 00:10:00 UTC
Referencje