Closed Loop Technology · Closed-Loop Technology Cless Server · CVE-2024-40125
**Name of the Vulnerable Software and Affected Versions**
Closed-Loop Technology CLESS Server version 4.5.2
**Description**
An arbitrary file upload vulnerability in the Media Manager function allows attackers to execute arbitrary code via uploading a crafted PHP file to the upload endpoint.
**Recommendations**
For version 4.5.2, consider disabling the Media Manager function until a patch is available to prevent arbitrary file uploads and subsequent code execution. Restrict access to the upload endpoint to minimize the risk of exploitation. Avoid using the Media Manager function in the affected version until the issue is resolved.