Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-47933 | A vulnerability was found in Flute CMS 0.2.2.4-alpha. It has been rated as critical. This issue affects the function replaceContent of the file app/Core/Support/ContentParser.php of the component Notification Handler. The manipulation leads to code injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272069 was assigned to this vulnerability. |
Thu, 05 Sep 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Flute-cms
Flute-cms flute |
|
| CPEs | cpe:2.3:a:flute-cms:flute:0.2.2.4:alpha:*:*:*:*:*:* | |
| Vendors & Products |
Flute-cms
Flute-cms flute |
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2024-08-01T21:45:38.384Z
Reserved: 2024-07-20T10:06:14.538Z
Link: CVE-2024-6947
Updated: 2024-08-01T21:45:38.384Z
Status : Modified
Published: 2024-07-21T09:15:03.267
Modified: 2026-06-17T08:19:02.827
Link: CVE-2024-6947
No data.
OpenCVE Enrichment
No data.
-
CWE-94
Improper Control of Generation of Code ('Code Injection')
EUVD