CVE-2024-41454 is an arbitrary file upload vulnerability in the UI login page logo upload function of Process Maker pm4core-docker version 4.1.21-RC7. This flaw allows authenticated attackers to execute arbitrary code by uploading specially crafted PHP or HTML files. Rated as Medium severity (CVSS 6.5), it requires high privileges but has low attack complexity, leading to high impact on confidentiality and integrity. Currently, there is no known public exploit code, Metasploit module, or active exploitation, and it has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | N/A | n/aCNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.