CVE-2024-58295 - CVE House
Back to Database
Status published High CVE-2024-58295

ElkArte Forum 1.1.9 Authenticated Remote Code Execution via Theme Upload

Vulnerability Description

ElkArte Forum 1.1.9 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the theme installation process. Attackers can upload a ZIP archive with a PHP file containing system commands, which can then be executed by accessing the uploaded file in the theme directory.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-58295

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • tmrswrr

Affected Vendor

Affected Software

ElkArte Forum
Vulnerable Versions:
1.1.9

Timeline

Official Publish: December 11th, 2025
Last Modified: December 16th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)