CVE-2024-26483
HIGHKirby CMS 4.1.0 - Arbitrary File Upload and Remote Code Execution via Profile Image Module
Title source: llmDescription
An arbitrary file upload vulnerability in the Profile Image module of Kirby CMS v4.1.0 allows attackers to execute arbitrary code via a crafted PDF file.
References (2)
Core 2
Core References
Third Party Advisory
https://github.com/getkirby/kirby/security/advisories/GHSA-xrvh-rvc4-5m43
Exploit, Third Party Advisory
https://shrouded-trowel-50c.notion.site/Kirby-CMS-4-1-0-Unrestricted-File-Upload-dc60ce3132f04442b73f2dba2631fae0?pvs=4
Scores
CVSS v3
8.8
EPSS
0.0097
EPSS Percentile
57.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-94
Status
published
Products (3)
getkirby/cms
0 - 3.6.6.5Packagist
getkirby/kirby
3.10.0
getkirby/kirby
< 3.6.6.5
Published
Feb 22, 2024
Tracked Since
Feb 18, 2026