PT-2024-23810 · Unknown · Youdiancms

Lucien

·

Published

2024-03-31

·

Updated

2025-06-30

·

CVE-2024-3117

CVSS v2.0

5.8

Medium

VectorAV:N/AC:L/Au:M/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions YouDianCMS versions up to 9.5.12
Description A critical issue was found in YouDianCMS, affecting the file AppLibActionAdminChannelAction.class.php. The manipulation of the file argument leads to unrestricted upload. This issue can be exploited remotely. The exploit has been disclosed publicly.
Recommendations For versions up to 9.5.12, as a temporary workaround, consider restricting access to the ChannelAction.class.php file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-3117

Affected Products

Youdiancms