RULE(RULE ID:337962)

Rule General Information
Release Date: 2024-04-29
Rule Name: 74CMS Arbitrary File Write Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: 74 CMS is a free website management system source code based on PHP + MYSQL, providing a comprehensive solution for building talent recruitment websites. It has a vulnerability allowing arbitrary file writing, enabling attackers to write malicious files for exploitation.
Impact: An attacker can write arbitrary files by constructing a specially crafted request, thus realizing unauthorized arbitrary file upload, which can eventually cause remote code execution.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.