74cms <=3.33 is vulnerable to remote code execution (RCE) in the background interface apiadmin.
                
            References
                    | Link | Resource | 
|---|---|
| https://gitee.com/Q16G/laravel_bug/blob/master/74cms.md | Permissions Required | 
| https://github.com/Q16G/cve_detail/blob/main/74cms/unzipRCE.md | Exploit Third Party Advisory | 
Configurations
                    History
                    28 May 2025, 17:39
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
 | |
| References | () https://gitee.com/Q16G/laravel_bug/blob/master/74cms.md - Permissions Required | |
| References | () https://github.com/Q16G/cve_detail/blob/main/74cms/unzipRCE.md - Exploit, Third Party Advisory | |
| CPE | cpe:2.3:a:74cms:74cms:*:*:*:*:*:*:*:* | |
| First Time | 74cms 74cms 74cms | 
18 Apr 2025, 14:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-04-18 13:15
Updated : 2025-05-28 17:39
NVD link : CVE-2024-46089
Mitre link : CVE-2024-46089
CVE.ORG link : CVE-2024-46089
JSON object : View
Products Affected
                74cms
- 74cms
CWE
                
                    
                        
                        CWE-77
                        
            Improper Neutralization of Special Elements used in a Command ('Command Injection')
