CVE-2024-58279
HIGHApprain - Unrestricted File Upload
Title source: ruleDescription
appRain CMF 4.0.5 contains an authenticated remote code execution vulnerability that allows administrative users to upload malicious PHP files through the filemanager upload endpoint. Attackers can leverage authenticated access to generate a web shell with command execution capabilities by uploading a crafted PHP file to the site's uploads directory.
Exploits (1)
exploitdb
WORKING POC
by Ahmet Ümit BAYRAM · pythonwebappsphp
https://www.exploit-db.com/exploits/52041
References (4)
Scores
CVSS v3
8.8
EPSS
0.0062
EPSS Percentile
70.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-434
Status
published
Products (2)
apprain/apprain
4.0.5
apprain/appRain CMF
4.0.5
Published
Dec 10, 2025
Tracked Since
Feb 18, 2026