High severity8.8NVD Advisory· Published Mar 25, 2024· Updated Jun 17, 2026
CVE-2024-29515
CVE-2024-29515
Description
File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP file to the save.php and config.php component.
Affected products
2- cpe:2.3:a:lepton-cms:leptoncms:7.1.0:*:*:*:*:*:*:*
- lepton/leptondescription
Patches
Vulnerability mechanics
News mentions
0No linked articles in our index yet.