Record summary

CVE-2024-58313 has a selected CVSS score of 8.6 (high); EIP currently links 1 catalogued exploit.

Description

xbtitFM 4.1.18 contains an insecure file upload vulnerability that allows authenticated attackers with administrative privileges to upload and execute arbitrary PHP code through the file_hosting feature. Attackers can bypass file type restrictions by modifying the Content-Type header to image/gif, adding GIF89a magic bytes, and using alternate PHP tags to upload web shells that execute system commands.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 16, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List4.1.18affected

Proofs of concept

1

Catalogued exploits

ExploitDBxbtitFM 4.1.18 - Multiple VulnerabilitiesExploitDB exploitby h5kj23kj32io2kjNot analyzed1 file

linked to 3 vulnerabilities

ExploitDB

PoC details

References

4