CVE-2024-52004 - CVE House
Back to Database
Status published High CVE-2024-52004

Remote code execution vulnerabilities in MediaCMS

Vulnerability Description

MediaCMS is an open source video and media CMS, written in Python/Django and React, featuring a REST API. MediaCMS has been prone to vulnerabilities that upon special cases can lead to remote code execution. All versions before v4.1.0 are susceptible, and users are highly recommended to upgrade. The vulnerabilities are related with insufficient input validation while uploading media content. The condition to exploit the vulnerability is that the portal allows users to upload content. This issue has been patched in version 4.1.0. There are no known workarounds for this vulnerability.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-52004

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

mediacms-io

View all reports →

Affected Software

mediacms
Vulnerable Versions:
< 4.1.0

Timeline

Official Publish: November 8th, 2024
Last Modified: November 12th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)