{"id":"GHSA-rhc2-23c2-ww7c","summary":"Remote code execution in web server context","details":"### Impact\nUser with administrative privileges and upload files that look like images but contain PHP code which can then be executed in the context of the web server.\n","aliases":["CVE-2024-37295"],"modified":"2024-06-11T21:14:02.296786Z","published":"2024-06-05T13:29:47Z","database_specific":{"cwe_ids":["CWE-73"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-06-05T13:29:47Z","nvd_published_at":"2024-06-11T15:16:09Z"},"references":[{"type":"WEB","url":"https://github.com/aimeos/aimeos-core/security/advisories/GHSA-rhc2-23c2-ww7c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-37295"},{"type":"PACKAGE","url":"https://github.com/aimeos/aimeos-core"}],"affected":[{"package":{"name":"aimeos/aimeos-core","ecosystem":"Packagist","purl":"pkg:composer/aimeos/aimeos-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2024.04.1"},{"fixed":"2024.04.5"}]}],"versions":["2024.04.1","2024.04.2","2024.04.3","2024.04.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/06/GHSA-rhc2-23c2-ww7c/GHSA-rhc2-23c2-ww7c.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}