CVE-2024-58295

CVSS

No CVSS.

E

lkArte Forum 1.1.9 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the theme installation process. Attackers can upload a ZIP archive with a PHP file containing system commands, which can then be executed by accessing the uploaded file in the theme directory.

Configurations

No configuration.

History

12 Dec 2025, 15:17

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-11 22:15

Updated : 2025-12-12 15:17


NVD link : CVE-2024-58295

Mitre link : CVE-2024-58295

CVE.ORG link : CVE-2024-58295


JSON object : View

Products Affected

No product.

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type