CVE-2024-31823 is a critical arbitrary code execution vulnerability affecting Ecommerce-CodeIgniter-Bootstrap, specifically in commit v. d22b54e8915f167a135046ceb857caaf8479c4da. This flaw, rated with a CVSS score of 8.8 (HIGH), allows a remote attacker with low privileges to execute arbitrary code through the removeSecondaryImage method in the Publish.php component. The attack complexity is low, and successful exploitation can lead to high impacts on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, nor are there public exploits or Metasploit modules available, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2024-01-02CPE matchmatch criteria | cpe:2.3:a:ecommerce-codeigniter-bootstrap_project:ecommerce-codeigniter-bootstrap:2024-01-02:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.