Vulnerability CVE-2024-9981


Published: 2024-10-15

Description:
The ee-class from FormosaSoft does not properly validate a specific page parameter, allowing remote attackers with regular privileges to upload a malicious PHP file first and then exploit this vulnerability to include the file, resulting in arbitrary code execution on the server.

Type:

CWE-98

(Improper Control of Filename for Include/Require Statement in PHP Program ('PHP File Inclusion'))

 References:
https://www.twcert.org.tw/tw/cp-132-8144-2885b-1.html
https://www.twcert.org.tw/en/cp-139-8145-15bea-2.html

Copyright 2024, cxsecurity.com

 

Back to Top