A specially crafted Zip file containing path traversal characters can be imported to the CyberPower PowerPanel server, which allows file writing to the server outside the intended scope, and could allow an attacker to achieve remote code execution.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2024-05-15T19:23:24.378Z

Updated: 2024-08-02T02:36:04.306Z

Reserved: 2024-04-29T16:47:22.325Z

Link: CVE-2024-33615

cve-icon Vulnrichment

Updated: 2024-05-16T15:13:19.064Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-05-15T20:15:12.687

Modified: 2024-05-16T13:03:05.353

Link: CVE-2024-33615

cve-icon Redhat

No data.