PT-2024-39927 · 07Flycrm+1 · 07Flycrm+1
Dee.Mirage
·
Published
2024-10-12
·
Updated
2025-07-30
·
CVE-2024-9903
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
07FLYCMS versions up to 1.2.0
07FLY-CMS versions up to 1.2.0
07FlyCRM versions up to 1.2.0
Description
A critical vulnerability has been found in the affected products, affecting the
fileUpload function of the file /admin/File/fileUpload. The manipulation of the file argument leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.Recommendations
For 07FLYCMS versions up to 1.2.0, consider disabling the
fileUpload function in the /admin/File/fileUpload file until a patch is available.
For 07FLY-CMS versions up to 1.2.0, restrict access to the /admin/File/fileUpload endpoint to minimize the risk of exploitation.
For 07FlyCRM versions up to 1.2.0, avoid using the file argument in the fileUpload function until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
07Flycms
07Flycrm