Description
The upload functionality of ASUS Download Master does not properly filter user input. Remote attackers with administrative privilege can exploit this vulnerability to upload any file to any location. They may even upload malicious web page files to the website directory, allowing arbitrary system commands to be executed upon browsing the webpage.
Published: 2024-06-14
Score: 7.2 High
EPSS: 1.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update to version 3.1.0.114 or later.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-29065 The upload functionality of ASUS Download Master does not properly filter user input. Remote attackers with administrative privilege can exploit this vulnerability to upload any file to any location. They may even upload malicious web page files to the website directory, allowing arbitrary system commands to be executed upon browsing the webpage.
History

No history.

Subscriptions

Asus Download Master
cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2024-08-02T01:46:04.773Z

Reserved: 2024-03-29T07:18:19.359Z

Link: CVE-2024-31161

cve-icon Vulnrichment

Updated: 2024-07-16T17:06:46.489Z

cve-icon NVD

Status : Modified

Published: 2024-06-14T04:15:42.323

Modified: 2024-11-21T09:12:56.600

Link: CVE-2024-31161

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses