An arbitrary file upload vulnerability in the Ticket Generation function of Ladybird Web Solution Faveo-Helpdesk v2.0.3 allows attackers to execute arbitrary code via uploading a crafted .html or .svg file.
Metrics
Affected Vendors & Products
References
History
Wed, 23 Oct 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Ladybirdweb
Ladybirdweb faveo Helpdesk |
|
Weaknesses | CWE-434 CWE-79 |
|
CPEs | cpe:2.3:a:ladybirdweb:faveo_helpdesk:*:*:*:*:*:*:*:* | |
Vendors & Products |
Ladybirdweb
Ladybirdweb faveo Helpdesk |
|
Metrics |
cvssV3_1
|
Tue, 22 Oct 2024 21:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An arbitrary file upload vulnerability in the Ticket Generation function of Ladybird Web Solution Faveo-Helpdesk v2.0.3 allows attackers to execute arbitrary code via uploading a crafted .html or .svg file. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-10-22T00:00:00
Updated: 2024-10-23T17:21:50.871Z
Reserved: 2024-09-11T00:00:00
Link: CVE-2024-46482
Vulnrichment
Updated: 2024-10-23T17:21:26.673Z
NVD
Status : Awaiting Analysis
Published: 2024-10-22T22:15:05.633
Modified: 2024-10-23T18:35:03.670
Link: CVE-2024-46482
Redhat
No data.