Medium severity4.7NVD Advisory· Published Dec 20, 2024· Updated Jun 17, 2026
CVE-2024-55342
CVE-2024-55342
Description
A file upload functionality in Piranha CMS 11.1 allows authenticated remote attackers to upload a crafted PDF file to /manager/media. This PDF can contain malicious JavaScript code, which is executed when a victim user opens or interacts with the PDF in their web browser, leading to a XSS vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
PiranhaNuGet | <= 11.1.0 | — |
Affected products
3- cpe:2.3:a:dotnetfoundation:piranha_cms:11.1:*:*:*:*:*:*:*
- Piranha CMS/Piranha CMSdescription
Patches
Vulnerability mechanics
References
3- sec-fortress.github.io/posts/articles/posts/CVE-2024-55342.htmlnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-cmwp-442x-3rcvghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-55342ghsaADVISORY
News mentions
0No linked articles in our index yet.