{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2024-6083","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2024-06-17T17:12:56.547Z","datePublished":"2024-06-17T23:31:03.508Z","dateUpdated":"2024-09-03T17:42:07.637Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2024-06-17T23:31:03.508Z"},"title":"PHPVibe Media Upload Page upload-mp3.php unrestricted upload","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-434","lang":"en","description":"CWE-434 Unrestricted Upload"}]}],"affected":[{"vendor":"n/a","product":"PHPVibe","versions":[{"version":"11.0.46","status":"affected"}],"modules":["Media Upload Page"]}],"descriptions":[{"lang":"en","value":"A vulnerability, which was classified as critical, was found in PHPVibe 11.0.46. Affected is an unknown function of the file /app/uploading/upload-mp3.php of the component Media Upload Page. The manipulation of the argument file leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-268824. NOTE: The vendor was contacted early about this disclosure but did not respond in any way."},{"lang":"de","value":"Es wurde eine Schwachstelle in PHPVibe 11.0.46 gefunden. Sie wurde als kritisch eingestuft. Betroffen hiervon ist ein unbekannter Ablauf der Datei /app/uploading/upload-mp3.php der Komponente Media Upload Page. Mittels Manipulieren des Arguments file mit unbekannten Daten kann eine unrestricted upload-Schwachstelle ausgenutzt werden. Umgesetzt werden kann der Angriff über das Netzwerk. Der Exploit steht zur öffentlichen Verfügung."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":5.3,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N","baseSeverity":"MEDIUM"}},{"cvssV3_1":{"version":"3.1","baseScore":6.3,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseSeverity":"MEDIUM"}},{"cvssV3_0":{"version":"3.0","baseScore":6.3,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseSeverity":"MEDIUM"}},{"cvssV2_0":{"version":"2.0","baseScore":6.5,"vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P"}}],"timeline":[{"time":"2024-06-17T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2024-06-17T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2024-06-17T19:18:14.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"weikang fu (VulDB User)","type":"reporter"}],"references":[{"url":"https://vuldb.com/?id.268824","name":"VDB-268824 | PHPVibe Media Upload Page upload-mp3.php unrestricted upload","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.268824","name":"VDB-268824 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.353552","name":"Submit #353552 | PHPVibe 11.0.46 Unrestricted Upload","tags":["third-party-advisory"]},{"url":"https://github.com/WeikFu/PHPVibe-vulnerability-description/issues/2","tags":["exploit","issue-tracking"]}]},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-01T21:25:03.307Z"},"title":"CVE Program Container","references":[{"url":"https://vuldb.com/?id.268824","name":"VDB-268824 | PHPVibe Media Upload Page upload-mp3.php unrestricted upload","tags":["vdb-entry","technical-description","x_transferred"]},{"url":"https://vuldb.com/?ctiid.268824","name":"VDB-268824 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required","x_transferred"]},{"url":"https://vuldb.com/?submit.353552","name":"Submit #353552 | PHPVibe 11.0.46 Unrestricted Upload","tags":["third-party-advisory","x_transferred"]},{"url":"https://github.com/WeikFu/PHPVibe-vulnerability-description/issues/2","tags":["exploit","issue-tracking","x_transferred"]}]},{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-09-03T17:41:54.279980Z","id":"CVE-2024-6083","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-09-03T17:42:07.637Z"}}]}}