CVE-2024-58295
HIGHElkArte Forum 1.1.9 - RCE
Title source: llmDescription
ElkArte Forum 1.1.9 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the theme installation process. Attackers can upload a ZIP archive with a PHP file containing system commands, which can then be executed by accessing the uploaded file in the theme directory.
Exploits (1)
References (4)
Scores
CVSS v4
8.6
EPSS
0.0075
EPSS Percentile
73.2%
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Details
CWE
CWE-434
Status
published
Products (1)
elkarte/ElkArte Forum
1.1.9
Published
Dec 11, 2025
Tracked Since
Feb 18, 2026