CVE-2024-46479

Venki Supravizio BPM through 18.0.1 was discovered to contain an arbitrary file upload vulnerability. An authenticated attacker may upload a malicious file, leading to remote code execution.
Configurations

Configuration 1 (hide)

cpe:2.3:a:venki:supravizio_bpm:*:*:*:*:*:*:*:*

History

07 Oct 2025, 16:49

Type Values Removed Values Added
References () https://github.com/Lorenzo-de-Sa/Vulnerability-Research - () https://github.com/Lorenzo-de-Sa/Vulnerability-Research - Third Party Advisory
References () https://github.com/Lorenzo-de-Sa/Vulnerability-Research/blob/main/CVE-2024-46479.md - () https://github.com/Lorenzo-de-Sa/Vulnerability-Research/blob/main/CVE-2024-46479.md - Third Party Advisory
References () https://www.venki.com.br/ferramenta-bpm/supravizio/ - () https://www.venki.com.br/ferramenta-bpm/supravizio/ - Product
First Time Venki supravizio Bpm
Venki
CPE cpe:2.3:a:venki:supravizio_bpm:*:*:*:*:*:*:*:*
Summary
  • (es) Se descubrió que Venki Supravizio BPM hasta la versión 18.0.1 contenía una vulnerabilidad de carga de archivos arbitrarios. Un atacante autenticado podría cargar un archivo malicioso, lo que provocaría la ejecución remota de código.

13 Jan 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-13 18:15

Updated : 2025-10-07 16:49


NVD link : CVE-2024-46479

Mitre link : CVE-2024-46479

CVE.ORG link : CVE-2024-46479


JSON object : View

Products Affected

venki

  • supravizio_bpm
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type