CVE-2024-11211

A vulnerability classified as critical has been found in EyouCMS up to 1.6.7. Affected is an unknown function of the component Website Logo Handler. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link Resource
https://github.com/falling-snow1/cve/blob/main/EyouCMS_RCE.md Broken Link
https://vuldb.com/?ctiid.284526 Permissions Required VDB Entry
https://vuldb.com/?id.284526 Permissions Required VDB Entry
https://vuldb.com/?submit.437600 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:eyoucms:eyoucms:*:*:*:*:*:*:*:*

History

19 Nov 2024, 19:01

Type Values Removed Values Added
First Time Eyoucms
Eyoucms eyoucms
CVSS v2 : 5.8
v3 : 4.7
v2 : 5.8
v3 : 7.2
CPE cpe:2.3:a:eyoucms:eyoucms:*:*:*:*:*:*:*:*
References () https://github.com/falling-snow1/cve/blob/main/EyouCMS_RCE.md - () https://github.com/falling-snow1/cve/blob/main/EyouCMS_RCE.md - Broken Link
References () https://vuldb.com/?ctiid.284526 - () https://vuldb.com/?ctiid.284526 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.284526 - () https://vuldb.com/?id.284526 - Permissions Required, VDB Entry
References () https://vuldb.com/?submit.437600 - () https://vuldb.com/?submit.437600 - Third Party Advisory, VDB Entry

15 Nov 2024, 13:58

Type Values Removed Values Added
Summary
  • (es) Se ha detectado una vulnerabilidad clasificada como crítica en EyouCMS hasta la versión 1.6.7. Se trata de una función desconocida del componente Website Logo Handler. La manipulación permite la carga sin restricciones. Es posible lanzar el ataque de forma remota. El exploit se ha hecho público y puede utilizarse. Se contactó al proveedor con anticipación sobre esta revelación, pero no respondió de ninguna manera.

15 Nov 2024, 09:15

Type Values Removed Values Added
Summary (en) A vulnerability classified as critical has been found in EyouCMS 1.5.6. Affected is an unknown function of the component Website Logo Handler. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. (en) A vulnerability classified as critical has been found in EyouCMS up to 1.6.7. Affected is an unknown function of the component Website Logo Handler. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

14 Nov 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-14 15:15

Updated : 2024-11-19 19:01


NVD link : CVE-2024-11211

Mitre link : CVE-2024-11211

CVE.ORG link : CVE-2024-11211


JSON object : View

Products Affected

eyoucms

  • eyoucms
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type

CWE-284

Improper Access Control