CVE-2024-25975
Arbitrary File Overwrite
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 6.5EPSS 0.6%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Ciclo de vida
29 may 2024Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
The application implements an up- and downvote function which alters a value within a JSON file. The POST parameters are not filtered properly and therefore an arbitrary file can be overwritten. The file can be controlled by an authenticated attacker, the content cannot be controlled. It is possible to overwrite all files for which the webserver has write access. It is required to supply a relative path (path traversal).
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Productos afectados
Interaction Design Team at the University of Applied Sciences and Arts in Hildesheim/Germany · HAWKI¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →