A vulnerability, which was classified as critical, was found in HkCms up to 2.3.2.240702. Affected is the function getFileName in the library /app/common/library/Upload.php. The manipulation leads to unrestricted upload.

This vulnerability is traded as CVE-2024-52677. It is possible to launch the attack remotely. There is no exploit available.