CVE-2024-37295
Last modified
CVE-2024-37295 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. Aimeos is an Open Source e-commerce framework for online shops. Starting in version 2024.01.1 and prior to version 2024.04.5, a user with administrative privileges can upload files that look like images but contain PHP code which can then be executed in the context of the web server. EPSS estimates a 0.61% chance of exploitation in the next 30 days.
Description
Aimeos is an Open Source e-commerce framework for online shops. Starting in version 2024.01.1 and prior to version 2024.04.5, a user with administrative privileges can upload files that look like images but contain PHP code which can then be executed in the context of the web server. Version 2024.04.5 fixes the issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-37295?
How severe is CVE-2024-37295?
How do I fix CVE-2024-37295?
Are you affected by CVE-2024-37295?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
