CVE-2024-24520

An issue in Lepton CMS v.7.0.0 allows a local attacker to execute arbitrary code via the upgrade.php file in the languages place.
Configurations

Configuration 1 (hide)

cpe:2.3:a:lepton-cms:leptoncms:7.0.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-03-21 02:52

Updated : 2025-05-01 15:03


NVD link : CVE-2024-24520

Mitre link : CVE-2024-24520

CVE.ORG link : CVE-2024-24520


JSON object : View

Products Affected

lepton-cms

  • leptoncms
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')