CVE-2024-31011 is a critical arbitrary file write vulnerability affecting beescms v.4.0. This flaw, residing in admin_template.php, allows a remote attacker to execute arbitrary code due to inadequate isolation of file paths and lack of suffix verification. With a CVSS score of 9.8 (Critical), it presents a severe risk, enabling full compromise of confidentiality, integrity, and availability without user interaction or authentication. Currently, there is no public exploit code available, no evidence of active exploitation, and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0CPE matchmatch criteria | cpe:2.3:a:beescms:beescms:4.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.