cve/2024/CVE-2024-4825.md
2024-05-25 21:48:12 +02:00

18 lines
787 B
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

### [CVE-2024-4825](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4825)
![](https://img.shields.io/static/v1?label=Product&message=Cockpit%20CMS&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3D%200.5.5%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-434%20Unrestricted%20Upload%20of%20File%20with%20Dangerous%20Type&color=brighgreen)
### Description
A vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in /media/api parameter via post request. An attacker could upload files to the server, compromising the entire infrastructure.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/fkie-cad/nvd-json-data-feeds