CVE-2024-45136

InCopy versions 19.4, 18.5.3 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution by an attacker. An attacker could exploit this vulnerability by uploading a malicious file which can then be executed on the server. Exploitation of this issue requires user interaction.
References
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:adobe:incopy:*:*:*:*:*:*:*:*
cpe:2.3:a:adobe:incopy:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-10-09 15:15

Updated : 2024-10-18 14:20


NVD link : CVE-2024-45136

Mitre link : CVE-2024-45136

CVE.ORG link : CVE-2024-45136


JSON object : View

Products Affected

adobe

  • incopy

apple

  • macos

microsoft

  • windows
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type