CVE-2024-33270
Severity CVSS v4.0:
Pending analysis
Type:
CWE-125
Out-of-bounds Read
Publication date:
30/04/2024
Last modified:
15/04/2026
Description
An issue in FME Modules fileuploads v.2.0.3 and before and fixed in v2.0.4 allows a remote attacker to obtain sensitive information via the uploadfiles.php component.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- http://fileuploads.com
- http://fme.com
- https://addons.prestashop.com/en/additional-information-product-tab/21373-customer-file-upload-attach-file-on-productcart-pages.html
- https://security.friendsofpresta.org/modules/2024/04/29/fileuploads.html
- http://fileuploads.com
- http://fme.com
- https://addons.prestashop.com/en/additional-information-product-tab/21373-customer-file-upload-attach-file-on-productcart-pages.html
- https://security.friendsofpresta.org/modules/2024/04/29/fileuploads.html



