PT-2024-28789 · Closed Loop Technology · Closed-Loop Technology Cless Server
Brendon Teo
·
Published
2024-09-19
·
Updated
2024-09-25
·
CVE-2024-40125
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Closed-Loop Technology CLESS Server version 4.5.2
Description
An arbitrary file upload vulnerability in the Media Manager function allows attackers to execute arbitrary code via uploading a crafted PHP file to the upload endpoint.
Recommendations
For version 4.5.2, consider disabling the Media Manager function until a patch is available to prevent arbitrary file uploads and subsequent code execution. Restrict access to the upload endpoint to minimize the risk of exploitation. Avoid using the Media Manager function in the affected version until the issue is resolved.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Closed-Loop Technology Cless Server