Today > vulnerabilities   -   You can now download lists of IOCs here!

CVE-2024-37879

Sept. 26, 2024, 1:32 p.m.

Product(s) Impacted

User-friendly SVN (USVN)

  • before v1.0.12

Description

Improper input validation in /admin/config/save in User-friendly SVN (USVN) before v1.0.12 and below allows administrators to execute arbitrary code via the fields "siteTitle", "siteIco" and "siteLogo".

Weaknesses

Date

Published: Sept. 20, 2024, 5:15 p.m.

Last Modified: Sept. 26, 2024, 1:32 p.m.

Status : Awaiting Analysis

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

cve@mitre.org

References