PT-2024-16325 · Wuzhicms · Wuzhi Cms

·

CVE-2024-10505

·

Published

2024-10-30

·

Updated

2024-11-06

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions wuzhicms version 4.1.0
Description A critical issue has been found, affecting the add/edit function of the file www/coreframe/app/content/admin/block.php. This leads to code injection and can be exploited remotely. The issue has been publicly disclosed, and the vendor was contacted but did not respond.
Recommendations For wuzhicms version 4.1.0, consider disabling the add/edit function in the www/coreframe/app/content/admin/block.php file as a temporary workaround until a patch is available. Restrict access to this function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-10505

Affected Products

Wuzhi Cms