vendor:
ElkArte Forum
by:
tmrswrr
6.1
CVSS
HIGH
Remote Code Execution (RCE)
94
CWE
Product Name: ElkArte Forum
Affected Version From: 1.1.2009
Affected Version To: 1.1.2009
Patch Exists: NO
Related CWE: Not available
CPE: a:elkarte:elkarte:1.1.9
Platforms Tested: Web
2024
ElkArte Forum 1.1.9 – Remote Code Execution (RCE) (Authenticated)
An authenticated remote code execution vulnerability exists in ElkArte Forum version 1.1.9. By uploading a malicious PHP file via the theme installation feature, an attacker can execute arbitrary commands on the server, leading to a compromise of the system.
Mitigation:
To mitigate this vulnerability, it is recommended to update the ElkArte Forum to a patched version as soon as the vendor releases a fix. Additionally, restrict access to the theme installation and file upload functionalities to trusted users only.