CVE-2024-58302 | Flarum Friendsof Pretty Mail 1.1.2 filename control (Exploit 51947 / EDB-51947)
A vulnerability identified as problematic has been detected in Flarum Friendsof Pretty Mail 1.1.2. Affected by this issue is some unknown functionality. Performing manipulation results in improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability is identified as CVE-2024-58302. The attack is only possible with local access. Additionally, an exploit exists.