CVE-2024-52291
CVSS 3.1 Score 8.4 of 10 (high)
Details
Summary
CVE-2024-52291 is a vulnerability affecting Craft CMS, a content management system. An attacker can exploit this issue by using a double file:// scheme to bypass local file system validation. This allows the attacker to specify sensitive folders as the file system, potentially leading to file overwriting through malicious uploads, unauthorized access to sensitive files, and in some cases, remote code execution via Server-Side Template Injection (SSTI). This vulnerability only affects users with authenticated administrator accounts with the allowAdminChanges feature enabled. Versions 5.4.6 and 4.12.5 have already been released to address this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- CMs
Affected Vendors
- Pluck -