Webopac from Grand Vice info does not properly validate uploaded file types, allowing unauthenticated remote attackers to upload and execute webshells, which could lead to arbitrary code execution on the server.
Metrics
Affected Vendors & Products
References
History
Mon, 11 Nov 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Vice
Vice webopac |
|
CPEs | cpe:2.3:a:vice:webopac:*:*:*:*:*:*:*:* | |
Vendors & Products |
Vice
Vice webopac |
|
Metrics |
ssvc
|
Mon, 11 Nov 2024 07:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Webopac from Grand Vice info does not properly validate uploaded file types, allowing unauthenticated remote attackers to upload and execute webshells, which could lead to arbitrary code execution on the server. | |
Title | Grand Vice info Webopac - Arbitrary File Upload | |
Weaknesses | CWE-434 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: twcert
Published: 2024-11-11T07:02:59.316Z
Updated: 2024-11-11T16:02:46.183Z
Reserved: 2024-11-08T05:54:42.229Z
Link: CVE-2024-11018
Vulnrichment
Updated: 2024-11-11T16:02:29.663Z
NVD
Status : Analyzed
Published: 2024-11-11T07:15:05.210
Modified: 2024-11-18T18:59:01.513
Link: CVE-2024-11018
Redhat
No data.