Roothub v2.5 was discovered to contain an arbitrary file upload vulnerability via the customPath parameter in the upload() function. This vulnerability allows attackers to execute arbitrary code via a crafted JSP file.

Project Subscriptions

Vendors Products
Roothub Subscribe
Roothub Subscribe
Roothub Project Subscribe
Roothub Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 01 May 2025 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Roothub
Roothub roothub
CPEs cpe:2.3:a:roothub:roothub:2.5.0:*:*:*:*:*:*:*
Vendors & Products Roothub
Roothub roothub

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-02T02:27:53.360Z

Reserved: 2024-04-23T00:00:00

Link: CVE-2024-33120

cve-icon Vulnrichment

Updated: 2024-05-07T18:36:08.552Z

cve-icon NVD

Status : Analyzed

Published: 2024-05-07T15:15:09.353

Modified: 2025-05-01T14:55:22.393

Link: CVE-2024-33120

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses