A vulnerability, which was classified as critical, was found in osuuu LightPicture up to 1.2.2. Affected is an unknown function of the file /app/controller/Setup.php. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-254856.
References
Link | Resource |
---|---|
https://note.zhaoj.in/share/FeCRflSHPLbj | Broken Link |
https://vuldb.com/?ctiid.254856 | Permissions Required |
https://vuldb.com/?id.254856 | Permissions Required |
https://note.zhaoj.in/share/FeCRflSHPLbj | Broken Link |
https://vuldb.com/?ctiid.254856 | Permissions Required |
https://vuldb.com/?id.254856 | Permissions Required |
Configurations
History
18 Dec 2024, 18:21
Type | Values Removed | Values Added |
---|---|---|
First Time |
Osuuu
Osuuu lightpicture |
|
References | () https://note.zhaoj.in/share/FeCRflSHPLbj - Broken Link | |
References | () https://vuldb.com/?ctiid.254856 - Permissions Required | |
References | () https://vuldb.com/?id.254856 - Permissions Required | |
CPE | cpe:2.3:a:osuuu:lightpicture:*:*:*:*:*:*:*:* |
Information
Published : 2024-02-27 15:15
Updated : 2024-12-18 18:21
NVD link : CVE-2024-1921
Mitre link : CVE-2024-1921
CVE.ORG link : CVE-2024-1921
JSON object : View
Products Affected
osuuu
- lightpicture
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type