CVE-2024-24550

A security vulnerability has been identified in Bludit, allowing attackers with knowledge of the API token to upload arbitrary files through the File API which leads to arbitrary code execution on the server. This vulnerability arises from improper handling of file uploads, enabling malicious actors to upload and execute PHP files.
CVSS

No CVSS.

Configurations

No configuration.

History

21 Nov 2024, 08:59

Type Values Removed Values Added
References () https://www.redguard.ch/blog/2024/06/20/security-advisory-bludit/ - () https://www.redguard.ch/blog/2024/06/20/security-advisory-bludit/ -

24 Jun 2024, 12:57

Type Values Removed Values Added
Summary
  • (es) Se ha identificado una vulnerabilidad de seguridad en Bludit, que permite a atacantes con conocimiento del token API cargar archivos arbitrarios a través de File API, lo que conduce a la ejecución de código arbitrario en el servidor. Esta vulnerabilidad surge del manejo inadecuado de la carga de archivos, lo que permite a actores malintencionados cargar y ejecutar archivos PHP.

24 Jun 2024, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-24 07:15

Updated : 2024-11-21 08:59


NVD link : CVE-2024-24550

Mitre link : CVE-2024-24550

CVE.ORG link : CVE-2024-24550


JSON object : View

Products Affected

No product.

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

CWE-434

Unrestricted Upload of File with Dangerous Type

CWE-502

Deserialization of Untrusted Data