Remote Code Execution & File Deletion in Asset Uploads
48Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.1epss 1.8%
from disclosure to weapon2 days
Published on NVDFeb 26
1st PoC+2d
exploitation probability
1.8%top 24% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
This advisory addresses two critical security vulnerabilities present in Mautic versions before 5.2.3. These vulnerabilities could be exploited by authenticated users.
* Remote Code Execution (RCE) via Asset Upload: A Remote Code Execution vulnerability has been identified in the asset upload functionality. Insufficient enforcement of allowed file extensions allows an attacker to bypass restrictions and upload executable files, such as PHP scripts.
* Path Traversal File Deletion: A Path Traversal vulnerability exists in the upload validation process. Due to improper handling of path components, an authenticated user can manipulate the file deletion process to delete arbitrary files on the host system.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
Affected products
Mautic · mautic/corepublic PoCs found — 2
githubgithub.com/mallo-m/CVE-2024-47051★ 4githubgithub.com/hyeonyeonglee/CVE-2024-47051★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.