We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-6647

Croogo Setting Theme unrestricted upload



AssignerVulDB
Reserved2024-07-10
Published2024-07-10
Updated2024-08-01

Description

EN DE

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in Croogo up to 4.0.7. This affects an unknown part of the file admin/settings/settings/prefix/Theme of the component Setting Handler. The manipulation of the argument Content-Type leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-271053 was assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Es wurde eine Schwachstelle in Croogo bis 4.0.7 entdeckt. Sie wurde als kritisch eingestuft. Dabei betrifft es einen unbekannter Codeteil der Datei admin/settings/settings/prefix/Theme der Komponente Setting Handler. Mit der Manipulation des Arguments Content-Type mit unbekannten Daten kann eine unrestricted upload-Schwachstelle ausgenutzt werden. Die Umsetzung des Angriffs kann dabei über das Netzwerk erfolgen. Der Exploit steht zur öffentlichen Verfügung.



MEDIUM: 5.1CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
MEDIUM: 4.7CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
MEDIUM: 4.7CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
5.8CVSS:2.0/AV:N/AC:L/Au:M/C:P/I:P/A:P

Problem types

CWE-434 Unrestricted Upload

Timeline

2024-07-10:Advisory disclosed
2024-07-10:VulDB entry created
2024-07-10:VulDB entry last update

Credits

Dee.Mirage (VulDB User) 0x4006ef9c10

References

https://vuldb.com/?id.271053 (VDB-271053 | Croogo Setting Theme unrestricted upload) vdb-entry technical-description

https://vuldb.com/?ctiid.271053 (VDB-271053 | CTI Indicators (IOB, IOC, TTP, IOA)) signature permissions-required

https://vuldb.com/?submit.372009 (Submit #372009 | croogo.org croogo v4.0.7 Upload) third-party-advisory

https://github.com/DeepMountains/Mirage/blob/main/CVE-1.md exploit

cve.org CVE-2024-6647

nvd.nist.gov CVE-2024-6647

Download JSON

Share this page
https://cve.threatint.com
Subscribe to our newsletter to learn more about our work.