CVE-2024-47946
CVE-2024-47946
Título es
CVE-2024-47946
Mar, 10/12/2024 – 08:15
Tipo
CWE-434
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2024-47946
Descripción en
If the attacker has access to a valid Poweruser session, remote code execution is possible because specially crafted valid PNG files with injected PHP content can be uploaded as desktop backgrounds or lock screens. After the upload, the PHP script is available in the web root. The PHP code executes once the uploaded file is accessed. This allows the execution of arbitrary PHP code and OS commands on the device as "www-data".
10/12/2024
10/12/2024
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis
Referencias
Enviar en el boletín
Off
