PT-2024-20794 · 71Cms · 71Cms

Published

2024-02-26

·

Updated

2025-05-23

·

CVE-2024-25166

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions 71CMS version 1.0.0
Description The issue allows a remote attacker to execute arbitrary code via the uploadfile action parameter in the controller.php file. This is a Cross Site Scripting vulnerability.
Recommendations For 71CMS version 1.0.0, consider disabling the uploadfile action parameter in the controller.php file as a temporary workaround until a patch is available. Restrict access to the controller.php file to minimize the risk of exploitation. Avoid using the uploadfile action parameter in the affected API endpoint until the issue is resolved.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-25166

Affected Products

71Cms