216.73.217.22

CVE-2024-52677

· Published 20/11/2024 21:15 · Modified 26/11/2024 19:15

Labels: CVE-2024-52677 2024-11-20CVE-2024-52677CWE-434[email protected]

Essential information

Published
20/11/2024 21:15
Modified
26/11/2024 19:15
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

HkCms <= v2.3.2.240702 is vulnerable to file upload in the getFileName method in /app/common/library/Upload.php.

NVD status

Status
Modified — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
hkcms / hkcms cpe:2.3:a:hkcms:hkcms:*:*:*:*:*:*:*:*

References