CVE-2024-56973

Insecure Permissions vulnerability in Alvaria, Inc Unified IP Unified Director before v.7.2SP2 allows a remote attacker to execute arbitrary code via the source and filename parameters to the ProcessUploadFromURL.jsp component.
Configurations

No configuration.

History

28 Feb 2025, 17:15

Type Values Removed Values Added
References () https://gist.github.com/VAMorales/1092a29ac7d0b4b80d5c853b9a22a65d - () https://gist.github.com/VAMorales/1092a29ac7d0b4b80d5c853b9a22a65d -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-281
Summary
  • (es) La vulnerabilidad de permisos inseguros en Alvaria, Inc Unified IP Unified Director anterior a v.7.2SP2 permite a un atacante remoto ejecutar código arbitrario a través de los parámetros de origen y nombre de archivo del componente ProcessUploadFromURL.jsp.

14 Feb 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-14 16:15

Updated : 2025-02-28 17:15


NVD link : CVE-2024-56973

Mitre link : CVE-2024-56973

CVE.ORG link : CVE-2024-56973


JSON object : View

Products Affected

No product.

CWE
CWE-281

Improper Preservation of Permissions