PT-2024-37986 · Flute Cms · Flute Cms

·

CVE-2024-6947

·

Published

2024-07-21

·

Updated

2024-09-05

CVSS v2.0

5.8

Medium

VectorAV:N/AC:L/Au:M/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Flute CMS version 0.2.2.4-alpha
Description A critical issue affects the replaceContent function of the ContentParser.php file in the Notification Handler component, leading to code injection. The attack can be initiated remotely.
Recommendations For Flute CMS version 0.2.2.4-alpha, consider disabling the replaceContent function of the ContentParser.php file until a patch is available. Restrict access to the Notification Handler component to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-6947

Affected Products

Flute Cms