PT-2024-27452 · Aimeos · Aimeos
Ssshah2131
·
Published
2024-06-05
·
Updated
2024-06-13
·
CVE-2024-37295
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Aimeos versions 2024.01.1 through 2024.04.4
Description
The issue allows a user with administrative privileges to upload files that appear to be images but actually contain PHP code, which can then be executed in the context of the web server.
Recommendations
For Aimeos versions 2024.01.1 through 2024.04.4, update to version 2024.04.5 to resolve the issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aimeos