PT-2024-39220 · Unknown · Bit File Manager

·

CVE-2024-8743

·

Published

2024-10-04

·

Updated

2025-01-10

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: The Bit File Manager versions up to, and including, 6.5.7
Description: The issue is due to a lack of proper checks on allowed file types, making it possible for authenticated attackers with Subscriber-level access and above, and granted permissions by an administrator, to upload .css and .js files. This could lead to Stored Cross-Site Scripting.
Recommendations: For versions up to, and including, 6.5.7, update to a version later than 6.5.7 to resolve the issue. As a temporary workaround, consider restricting file uploads to only necessary file types until a patch is available. Restrict access to the file upload feature to minimize the risk of exploitation.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-8743

Affected Products

Bit File Manager