Overview
- Description
- MediaCMS is an open source video and media CMS, written in Python/Django and React, featuring a REST API. MediaCMS has been prone to vulnerabilities that upon special cases can lead to remote code execution. All versions before v4.1.0 are susceptible, and users are highly recommended to upgrade. The vulnerabilities are related with insufficient input validation while uploading media content. The condition to exploit the vulnerability is that the portal allows users to upload content. This issue has been patched in version 4.1.0. There are no known workarounds for this vulnerability.
- Source
- security-advisories@github.com
- NVD status
- Awaiting Analysis
Risk scores
CVSS 4.0
- Type
- Secondary
- Base score
- 8.7
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- HIGH
Weaknesses
- security-advisories@github.com
- CWE-74
Social media
- Hype score
- Not currently trending
CVE-2024-52004 Remote Code Execution Vulnerability in MediaCMS Prior to v4.1.0 MediaCMS is a tool for managing video and media, built with Python/Django and React and uses a REST API. Before version 4.1.0, it's v... https://t.co/TFSQiSyDdI
@VulmonFeeds
9 Nov 2024
29 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2024-52004 MediaCMS is an open source video and media CMS, written in Python/Django and React, featuring a REST API. MediaCMS has been prone to vulnerabilities that upon special… https://t.co/yLyqLt5wWY
@CVEnew
8 Nov 2024
354 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[CVE-2024-52004: HIGH] MediaCMS, a Python/Django-based open-source video CMS, had remote code execution vulnerabilities. Upgrade to v4.1.0 to fix issues from versions before.#cybersecurity,#vulnerability https://t.co/IGrMI6r6yT https://t.co/6yDczznpd3
@CveFindCom
8 Nov 2024
31 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes