CVE-2024-29368

MEDIUM

MoziloCMS v2.0 - File Upload

Title source: llm
STIX 2.1

Description

An arbitrary file upload vulnerability in the file handling module of moziloCMS v2.0 allows attackers to bypass extension restrictions via file renaming, potentially leading to unauthorized file execution or storage of malicious content.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0012
EPSS Percentile 31.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-434
Status published
Products (1)
mozilo/mozilocms 2.0
Published Apr 22, 2024
Tracked Since Feb 18, 2026