xbtitFM 4.1.18 Insecure File Upload in file_hosting Feature
Vulnerability Description
xbtitFM 4.1.18 contains an insecure file upload vulnerability that allows authenticated attackers with administrative privileges to upload and execute arbitrary PHP code through the file_hosting feature. Attackers can bypass file type restrictions by modifying the Content-Type header to image/gif, adding GIF89a magic bytes, and using alternate PHP tags to upload web shells that execute system commands.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-58313
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- xbtitFM Team
References
Affected Vendor
xbtitfm
View all reports →