CVE-2024-34982
LyLme-Spage - Arbitary File Upload
Record summary
CVE-2024-34982 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
An arbitrary file upload vulnerability in the component /include/file.php of lylme_spage v1.9.5 allows attackers to execute arbitrary code via uploading a crafted file.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated May 17, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
lylme_spageBrowse lylme / lylme_spageDefault status: unknown | CVE List | 1.9.5 | affected |
Nuclei templates
1ProjectDiscoveryHIGHLyLme-Spage - Arbitary File Upload
An arbitrary file upload vulnerability in the component /include/file.php of lylme_spage v1.9.5 allows attackers to execute arbitrary code via uploading a crafted file.
Impact
Attackers can upload arbitrary files to execute malicious code on the LyLme-Spage server.
Remediation
Update LyLme Spage to a version later than 1.9.5 that patches the arbitrary file upload vulnerability.
Source: ProjectDiscovery