PT-2024-34303 · Mahlamusa · Multi Purpose Mail Form
Stealthcopter
·
Published
2024-11-04
·
Updated
2026-01-23
·
CVE-2024-50526
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Multi Purpose Mail Form versions n/a through 1.0.2
Description:
The issue allows users to upload dangerous files, potentially leading to a web server compromise by uploading a web shell. This can happen due to an unrestricted upload of file with dangerous type vulnerability in the Multi Purpose Mail Form by mahlamusa.
Recommendations:
For versions n/a through 1.0.2, consider disabling the file upload feature until a patch is available to prevent potential exploitation. Restrict access to the mail form to minimize the risk of uploading dangerous files. Avoid using the mail form for uploading files until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Multi Purpose Mail Form