← Back to browse · API

CVE-2024-34982

Severity
CRITICAL
CVSS
9.8
EPSS
0.04675
Risk score
40.84
CISA KEV
No
PoC
No
Published
2024-05-17
Modified
2025-02-13
First seen
2026-08-07
Aliases
EUVD-2024-35135, GHSA-C4MM-9H9F-6XF6
Products
n/a:n/a n/a
Sources
euvd EUVD-2024-35135

Description

An arbitrary file upload vulnerability in the component /include/file.php of lylme_spage v1.9.5 allows attackers to execute arbitrary code via uploading a crafted file.

References