PT-2024-27452 · Aimeos · Aimeos

Ssshah2131

·

Published

2024-06-05

·

Updated

2024-06-13

·

CVE-2024-37295

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Aimeos versions 2024.01.1 through 2024.04.4
Description The issue allows a user with administrative privileges to upload files that appear to be images but actually contain PHP code, which can then be executed in the context of the web server.
Recommendations For Aimeos versions 2024.01.1 through 2024.04.4, update to version 2024.04.5 to resolve the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-37295
GHSA-RHC2-23C2-WW7C

Affected Products

Aimeos