{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2024-6947","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2024-07-20T10:06:14.538Z","datePublished":"2024-07-21T09:00:07.017Z","dateUpdated":"2024-08-01T21:45:38.384Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2024-07-21T09:00:07.017Z"},"title":"Flute CMS Notification ContentParser.php replaceContent code injection","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-94","lang":"en","description":"CWE-94 Code Injection"}]}],"affected":[{"vendor":"Flute","product":"CMS","versions":[{"version":"0.2.2.4-alpha","status":"affected"}],"modules":["Notification Handler"]}],"descriptions":[{"lang":"en","value":"A vulnerability was found in Flute CMS 0.2.2.4-alpha. It has been rated as critical. This issue affects the function replaceContent of the file app/Core/Support/ContentParser.php of the component Notification Handler. The manipulation leads to code injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272069 was assigned to this vulnerability."},{"lang":"de","value":"Eine Schwachstelle wurde in Flute CMS 0.2.2.4-alpha ausgemacht. Sie wurde als kritisch eingestuft. Hierbei geht es um die Funktion replaceContent der Datei app/Core/Support/ContentParser.php der Komponente Notification Handler. Mittels Manipulieren mit unbekannten Daten kann eine code injection-Schwachstelle ausgenutzt werden. Umgesetzt werden kann der Angriff über das Netzwerk. Der Exploit steht zur öffentlichen Verfügung."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":5.1,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N","baseSeverity":"MEDIUM"}},{"cvssV3_1":{"version":"3.1","baseScore":4.7,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L","baseSeverity":"MEDIUM"}},{"cvssV3_0":{"version":"3.0","baseScore":4.7,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L","baseSeverity":"MEDIUM"}},{"cvssV2_0":{"version":"2.0","baseScore":5.8,"vectorString":"AV:N/AC:L/Au:M/C:P/I:P/A:P"}}],"timeline":[{"time":"2024-07-20T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2024-07-20T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2024-07-20T12:11:26.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"Dee.Mirage (VulDB User)","type":"reporter"}],"references":[{"url":"https://vuldb.com/?id.272069","name":"VDB-272069 | Flute CMS Notification ContentParser.php replaceContent code injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.272069","name":"VDB-272069 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.376785","name":"Submit #376785 | flute-cms.com Web-based CMS for server games written on PHP v0.2.2.4-alpha SSTi","tags":["third-party-advisory"]},{"url":"https://github.com/DeepMountains/Mirage/blob/main/CVE5-3.md","tags":["exploit"]}]},"adp":[{"affected":[{"vendor":"flute","product":"cms","cpes":["cpe:2.3:a:flute:cms:0.2.2.4-alpha:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"0.2.2.4-alpha","status":"affected"}]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-07-23T14:59:06.857639Z","id":"CVE-2024-6947","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-07-23T15:00:10.310Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-01T21:45:38.384Z"},"title":"CVE Program Container","references":[{"url":"https://vuldb.com/?id.272069","name":"VDB-272069 | Flute CMS Notification ContentParser.php replaceContent code injection","tags":["vdb-entry","technical-description","x_transferred"]},{"url":"https://vuldb.com/?ctiid.272069","name":"VDB-272069 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required","x_transferred"]},{"url":"https://vuldb.com/?submit.376785","name":"Submit #376785 | flute-cms.com Web-based CMS for server games written on PHP v0.2.2.4-alpha SSTi","tags":["third-party-advisory","x_transferred"]},{"url":"https://github.com/DeepMountains/Mirage/blob/main/CVE5-3.md","tags":["exploit","x_transferred"]}]}]}}