CVE-2024-30248
Last modified
CVE-2024-30248 is a high-severity vulnerability rated 7.7/10 on the CVSS scale. Piccolo Admin is an admin interface/content management system for Python, built on top of Piccolo. Piccolo's admin panel allows media files to be uploaded. EPSS estimates a 0.49% chance of exploitation in the next 30 days.
Description
Piccolo Admin is an admin interface/content management system for Python, built on top of Piccolo. Piccolo's admin panel allows media files to be uploaded. As a default, SVG is an allowed file type for upload. An attacker can upload an SVG which when loaded can allow arbitrary access to the admin page. This vulnerability was patched in version 1.3.2.
Metrics
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-30248?
How severe is CVE-2024-30248?
How do I fix CVE-2024-30248?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-30242Improper Neutralization of Special Elements used in an SQL C…8.5
- CVE-2024-30243Improper Neutralization of Special Elements used in an SQL C…8.5
- CVE-2024-30244Improper Neutralization of Special Elements used in an SQL C…8.8
- CVE-2024-30245Improper Neutralization of Special Elements used in an SQL C…7.6
- CVE-2024-30246Tuleap is an Open Source Suite to improve management of soft…7.1
- CVE-2024-30247NextcloudPi is a ready to use image for Virtual Machines, Ra…9.8
- CVE-2024-30249Cloudburst Network provides network components used within C…8.6
- CVE-2024-3025mintplex-labs/anything-llm is vulnerable to path traversal a…9.9
- CVE-2024-30250Astro-Shield is an integration to enhance website security w…7.5
- CVE-2024-30251aiohttp is an asynchronous HTTP client/server framework for …7.5
- CVE-2024-30252Livemarks is a browser extension that provides RSS feed book…2.6
- CVE-2024-30253@solana/web3.js is the Solana JavaScript SDK. Using particul…7.5
Are you affected by CVE-2024-30248?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
