PT-2024-37986 · Flute Cms · Flute Cms

Dee.Mirage

·

Published

2024-07-21

·

Updated

2024-09-05

·

CVE-2024-6947

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Flute CMS version 0.2.2.4-alpha
Description A critical issue affects the replaceContent function of the ContentParser.php file in the Notification Handler component, leading to code injection. The attack can be initiated remotely.
Recommendations For Flute CMS version 0.2.2.4-alpha, consider disabling the replaceContent function of the ContentParser.php file until a patch is available. Restrict access to the Notification Handler component to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-6947

Affected Products

Flute Cms