PT-2025-3229 · Unknown · Acf City Selector

Muhamad Agil Fachrian

·

Published

2025-01-02

·

Updated

2025-01-02

·

CVE-2024-56264

CVSS v3.1

6.6

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions ACF City Selector versions 1.14.0 and earlier
Description The issue allows for the unrestricted upload of files with dangerous types, enabling the upload of a web shell to a web server. This can be exploited by uploading malicious files.
Recommendations For versions 1.14.0 and earlier, update to a version that fixes this issue, as the current version allows for the upload of dangerous file types. As a temporary workaround, consider restricting file uploads to only allow safe file types until a patch is available.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-56264

Affected Products

Acf City Selector