CyberRota Analysis
AI-GeneratedCuteNews v2.1.2 is vulnerable to an unrestricted file upload flaw in the media.php module, allowing authenticated users with Media Manager access to upload malicious files. This could enable attackers to execute arbitrary code, potentially gaining remote server access through a reverse shell. Organizations using this version should prioritize patching to mitigate the risk of unauthorized access and potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Unrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.1.2 allows remote authenticated users with access to the Media Manager panel to execute arbitrary code in the context of the web application, leading to remote server access by triggering a reverse shell.