CVE-2024-52291

CVSS 3.1 Score 8.4 of 10 (high)

Details

Published Nov 13, 2024
Updated: Nov 15, 2024
CWE ID 22

Summary

CVE-2024-52291 is a vulnerability affecting Craft CMS, a content management system. An attacker can exploit this issue by using a double file:// scheme to bypass local file system validation. This allows the attacker to specify sensitive folders as the file system, potentially leading to file overwriting through malicious uploads, unauthorized access to sensitive files, and in some cases, remote code execution via Server-Side Template Injection (SSTI). This vulnerability only affects users with authenticated administrator accounts with the allowAdminChanges feature enabled. Versions 5.4.6 and 4.12.5 have already been released to address this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share