Security Advisory

CVE-2024-7917

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-08-18 22:31:07
Last updated 2024-08-19 16:04:33
Assigner VulDB
State PUBLISHED

Description

A vulnerability, which was classified as critical, has been found in DouPHP 1.7 Release 20220822. Affected by this issue is some unknown functionality of the file /admin/system.php of the component Favicon Handler. The manipulation of the argument site_favicon leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.