Improper input validation in /admin/config/save in User-friendly SVN (USVN) before v1.0.12 and below allows administrators to execute arbitrary code via the fields "siteTitle", "siteIco" and "siteLogo".
Metrics
Affected Vendors & Products
References
History
Fri, 01 Nov 2024 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-79 | |
Metrics |
cvssV3_1
|
Fri, 20 Sep 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 20 Sep 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper input validation in /admin/config/save in User-friendly SVN (USVN) before v1.0.12 and below allows administrators to execute arbitrary code via the fields "siteTitle", "siteIco" and "siteLogo". | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-11-01T20:47:08.246Z
Reserved: 2024-06-10T00:00:00
Link: CVE-2024-37879

Updated: 2024-09-20T17:56:14.467Z

Status : Awaiting Analysis
Published: 2024-09-20T17:15:14.970
Modified: 2024-11-01T21:35:02.967
Link: CVE-2024-37879

No data.