CVE-2024-11313

The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.
Configurations

Configuration 1 (hide)

cpe:2.3:a:trcore:dvc:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-11-18 07:15

Updated : 2024-11-20 15:16


NVD link : CVE-2024-11313

Mitre link : CVE-2024-11313

CVE.ORG link : CVE-2024-11313


JSON object : View

Products Affected

trcore

  • dvc
CWE
CWE-23

Relative Path Traversal

CWE-434

Unrestricted Upload of File with Dangerous Type

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')