A unrestricted upload of file with dangerous type vulnerability in epaper draft function in Corporate Training Management System before 10.13 allows remote authenticated users to bypass file upload restrictions and perform arbitrary system commands with SYSTEM privilege via a crafted ZIP file.
References
Link | Resource |
---|---|
https://zuso.ai/advisory/za-2024-10 |
Configurations
No configuration.
History
20 Dec 2024, 18:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
19 Dec 2024, 04:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-12-19 04:15
Updated : 2024-12-20 18:15
NVD link : CVE-2024-11984
Mitre link : CVE-2024-11984
CVE.ORG link : CVE-2024-11984
JSON object : View
Products Affected
No product.
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type