CVE-2024-37868 is a critical file upload vulnerability in Itsourcecode Online Discussion Forum Project v1.0, specifically affecting the "emiloimagtolis online_discussion_forum" product. This flaw allows a remote, authenticated attacker to execute arbitrary code by uploading malicious files via the "sendreply.php" script, which improperly handles user-supplied input. With a CVSS score of 8.8 (High), the vulnerability presents a significant risk of complete compromise of confidentiality, integrity, and availability. While no public exploits (Metasploit, Nuclei, ExploitDB) or active exploitation have been identified, and community discussion is minimal, its high EPSS score suggests a non-negligible probability of future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:emiloimagtolis:online_discussion_forum:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.