CVE Database
/

CVE-2024-58313

Back to search

CVE-2024-58313

Published: Dec 11, 2025

Modified: Apr 7, 2026

PUBLISHED

Description

xbtitFM 4.1.18 contains an insecure file upload vulnerability that allows authenticated attackers with administrative privileges to upload and execute arbitrary PHP code through the file_hosting feature. Attackers can bypass file type restrictions by modifying the Content-Type header to image/gif, adding GIF89a magic bytes, and using alternate PHP tags to upload web shells that execute system commands.

VendorProductVersions

xbtitfm

xbtitFM

affected
4.1.18

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now