CVE-2024-38529 is a Remote Code Execution (RCE) vulnerability affecting Admidio, an open-source user management system, in versions prior to 4.3.10. This flaw allows authenticated attackers to upload malicious PHP files via the Message module due to insufficient file extension verification. The uploaded files are publicly accessible, enabling RCE. Rated 8.8 HIGH on CVSS, this vulnerability has a low attack complexity and requires only low privileges, posing a significant risk of complete compromise (confidentiality, integrity, and availability). While the EPSS score is low, indicating a lower probability of exploitation compared to many CVEs, the FAUCET Risk Score is high at 82/100. Currently, there is no evidence of active exploitation, nor are there publicly available exploits in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, which is typical for a large percentage of reported vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.3.10CPE matchmatch criteria | cpe:2.3:a:admidio:admidio:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.