VYPR
Critical severity9.8NVD Advisory· Published Apr 3, 2024· Updated Jun 17, 2026

CVE-2024-31011

CVE-2024-31011

Description

Arbitrary file write vulnerability in beescms v.4.0, allows a remote attacker to execute arbitrary code via a file path that was not isolated and the suffix was not verified in admin_template.php.

Affected products

3
  • BeesCMS/BeesCMS2 versions
    cpe:2.3:a:beescms:beescms:4.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:beescms:beescms:4.0:*:*:*:*:*:*:*
    • (no CPE)range: =4.0
  • beescms/beescmsdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.