Critical severity9.8NVD Advisory· Published May 14, 2024· Updated Jun 17, 2026
CVE-2024-4825
CVE-2024-4825
Description
A vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in ‘/media/api’ parameter via post request. An attacker could upload files to the server, compromising the entire infrastructure.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
cockpit-hq/cockpitPackagist | < 2.7.0 | 2.7.0 |
Affected products
3Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-vpj8-xfqc-jcv9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-4825ghsaADVISORY
- www.incibe.es/en/incibe-cert/notices/aviso/unrestricted-upload-file-dangerous-type-vulnerability-cockpit-cmsnvdThird Party AdvisoryWEB
News mentions
0No linked articles in our index yet.