CVE-2024-12700
Tibbo AggreGate Network Manager Unrestricted Upload of File with Dangerous Type
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.7EPSS 0.6%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
19 Dec 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
There is an unrestricted file upload vulnerability where it is possible for an authenticated user (low privileged) to upload an jsp shell and execute code with the privileges of user running the web server.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Tibbo · AggreGate Network Manager