{"id":"GHSA-47mc-qmh2-mqj4","summary":"Automad arbitrary file upload vulnerability","details":"An arbitrary file upload vulnerability in the image upload function of Automad v2.0.0 allows attackers to execute arbitrary code via a crafted file.\n\nThe malicious file has to be prepared and uploaded manually by the admin. Usually there is only one admin per site and that is the owner.","aliases":["CVE-2024-40400"],"modified":"2024-11-19T05:35:03.224430Z","published":"2024-07-19T21:31:11Z","database_specific":{"github_reviewed_at":"2024-07-19T22:39:49Z","nvd_published_at":"2024-07-19T19:15:09Z","cwe_ids":["CWE-434"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-40400"},{"type":"WEB","url":"https://github.com/marcantondahmen/automad/issues/106"},{"type":"WEB","url":"https://github.com/marcantondahmen/automad/commit/112f070ccf423931c9bb2b36f9a26c345e1ef56e"},{"type":"PACKAGE","url":"https://github.com/marcantondahmen/automad"}],"affected":[{"package":{"name":"automad/automad","ecosystem":"Packagist","purl":"pkg:composer/automad/automad"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.0-alpha.5"}]}],"versions":["1.10.9","2.0.0-alpha.1","2.0.0-alpha.2","2.0.0-alpha.3","2.0.0-alpha.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/07/GHSA-47mc-qmh2-mqj4/GHSA-47mc-qmh2-mqj4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}