ElkArte Forum 1.1.9 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the theme installation process. Attackers can upload a ZIP archive with a PHP file containing system commands, which can then be executed by accessing the uploaded file in the theme directory.
History

Fri, 12 Dec 2025 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Elkarte
Elkarte forum
Vendors & Products Elkarte
Elkarte forum

Thu, 11 Dec 2025 21:45:00 +0000

Type Values Removed Values Added
Description ElkArte Forum 1.1.9 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the theme installation process. Attackers can upload a ZIP archive with a PHP file containing system commands, which can then be executed by accessing the uploaded file in the theme directory.
Title ElkArte Forum 1.1.9 Authenticated Remote Code Execution via Theme Upload
Weaknesses CWE-434
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-12-11T21:36:36.477Z

Updated: 2025-12-11T21:36:36.477Z

Reserved: 2025-12-11T00:58:28.456Z

Link: CVE-2024-58295

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-12-11T22:15:50.583

Modified: 2025-12-11T22:15:50.583

Link: CVE-2024-58295

cve-icon Redhat

No data.