A security vulnerability has been identified in Bludit, allowing attackers with knowledge of the API token to upload arbitrary files through the File API which leads to arbitrary code execution on the server. This vulnerability arises from improper handling of file uploads, enabling malicious actors to upload and execute PHP files.
CVSS

No CVSS.

History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: NCSC.ch

Published: 2024-06-24T07:05:50.655Z

Updated: 2024-06-24T13:33:38.619Z

Reserved: 2024-01-25T14:02:00.526Z


Link: CVE-2024-24550

JSON object: View

cve-icon NVD Information

Status : Awaiting Analysis

Published: 2024-06-24T07:15:13.580

Modified: 2024-06-24T12:57:36.513


Link: CVE-2024-24550

JSON object: View

cve-icon Redhat Information

No data.