PT-2024-28789 · Closed Loop Technology · Closed-Loop Technology Cless Server

Brendon Teo

·

Published

2024-09-19

·

Updated

2024-09-25

·

CVE-2024-40125

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Closed-Loop Technology CLESS Server version 4.5.2
Description An arbitrary file upload vulnerability in the Media Manager function allows attackers to execute arbitrary code via uploading a crafted PHP file to the upload endpoint.
Recommendations For version 4.5.2, consider disabling the Media Manager function until a patch is available to prevent arbitrary file uploads and subsequent code execution. Restrict access to the upload endpoint to minimize the risk of exploitation. Avoid using the Media Manager function in the affected version until the issue is resolved.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-40125

Affected Products

Closed-Loop Technology Cless Server