Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-32491

Опубликовано: 29 апр. 2024
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

An issue was discovered in Znuny and Znuny LTS 6.0.31 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in user can upload a file (via a manipulated AJAX Request) to an arbitrary writable location by traversing paths. Arbitrary code can be executed if this location is publicly available through the web server.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:znuny:znuny:*:*:*:*:lts:*:*:*
Версия от 6.0.31 (включая) до 6.5.7 (включая)
cpe:2.3:a:znuny:znuny:*:*:*:*:-:*:*:*
Версия от 7.0.1 (включая) до 7.0.16 (включая)

EPSS

Процентиль: 69%
0.00585
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 2 года назад

An issue was discovered in Znuny and Znuny LTS 6.0.31 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in user can upload a file (via a manipulated AJAX Request) to an arbitrary writable location by traversing paths. Arbitrary code can be executed if this location is publicly available through the web server.

CVSS3: 9.8
debian
почти 2 года назад

An issue was discovered in Znuny and Znuny LTS 6.0.31 through 6.5.7 an ...

CVSS3: 9.8
github
почти 2 года назад

An issue was discovered in Znuny and Znuny LTS 6.0.31 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in user can upload a file (via a manipulated AJAX Request) to an arbitrary writable location by traversing paths. Arbitrary code can be executed if this location is publicly available through the web server.

EPSS

Процентиль: 69%
0.00585
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-94