PT-2024-27804 · Twcms · Twcms

Sylvieverykawaii

·

Published

2024-06-12

·

Updated

2025-03-13

·

CVE-2024-37878

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions TWCMS version 2.0.3
Description The issue allows a remote attacker to execute arbitrary code. This is achieved via the "/TWCMS-gh-pages/twcms/runtime/twcms view/default,index.htm.php" endpoint, where PHP directly echoes parameters input from external sources, specifically the parameters input from external sources.
Recommendations For TWCMS version 2.0.3, consider disabling the direct echoing of parameters from external sources in the PHP code until a patch is available. Restrict access to the "/TWCMS-gh-pages/twcms/runtime/twcms view/default,index.htm.php" endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-37878

Affected Products

Twcms