← voltar
CVE-2024-58279

appRain CMF 4.0.5 Authenticated Remote Code Execution via Filemanager Upload

CVSS 8.6 HIGHEPSS 0.8%CWE-434
Vexday Risk Score
21Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 8.6EPSS 0.8%KEV nãoPoC Nuclei Metasploit Patch referenciado
Ciclo de vida
10 dez 2025Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
appRain CMF 4.0.5 contains an authenticated remote code execution vulnerability that allows administrative users to upload malicious PHP files through the filemanager upload endpoint. Attackers can leverage authenticated access to generate a web shell with command execution capabilities by uploading a crafted PHP file to the site's uploads directory.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Produtos afetados
apprain · appRain CMF

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →