Unrated severityNVD Advisory· Published Dec 10, 2025· Updated Apr 7, 2026
Dotclear 2.29 Remote Code Execution via Authenticated File Upload
CVE-2024-58281
Description
Dotclear 2.29 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the media upload functionality. Attackers can exploit the file upload process by crafting a PHP shell with a command execution form to gain system access through the uploaded file.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.exploit-db.com/exploits/52037mitreexploit
- www.vulncheck.com/advisories/dotclear-remote-code-execution-via-authenticated-file-uploadmitrethird-party-advisory
News mentions
0No linked articles in our index yet.