PT-2025-50749 · Elkarte · Elkarte Forum

Tmrswrr

·

Published

2025-12-11

·

Updated

2025-12-11

·

CVE-2024-58295

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions ElkArte Forum version 1.1.9
Description Authenticated administrators can achieve remote code execution by uploading malicious PHP files during the theme installation process. This is possible by uploading a ZIP archive containing a PHP file with system commands, which is then executed when the file is accessed within the theme directory.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-58295

Affected Products

Elkarte Forum