CVE-2024-46089
MEDIUM74cms <= 3.33.0 - Remote Code Execution via Background API Interface
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-46089. PoCs published by Q16G.
AI-analyzed exploit summary The document describes a vulnerability in 74cms where the background API allows arbitrary file downloads and subsequent decompression, enabling an attacker to upload a malicious package. The exploit involves crafting a ZIP file with a specific structure and using API endpoints to download and unzip it, bypassing security checks.
Description
74cms <=3.33 is vulnerable to remote code execution (RCE) in the background interface apiadmin.
Exploits (1)
The document describes a vulnerability in 74cms where the background API allows arbitrary file downloads and subsequent decompression, enabling an attacker to upload a malicious package. The exploit involves crafting a ZIP file with a specific structure and using API endpoints to download and unzip it, bypassing security checks.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L