An authenticated arbitrary file upload vulnerability in the /documentCache/upload endpoint of InfoDom Performa 365 v4.0.1 allows attackers to execute arbitrary code via uploading a crafted SVG file.
Metrics
Affected Vendors & Products
References
History
Wed, 11 Dec 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-434 | |
Metrics |
cvssV3_1
|
Tue, 03 Dec 2024 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An authenticated arbitrary file upload vulnerability in the /documentCache/upload endpoint of InfoDom Performa 365 v4.0.1 allows attackers to execute arbitrary code via uploading a crafted SVG file. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-12-03T00:00:00
Updated: 2024-12-11T14:36:16.491Z
Reserved: 2024-09-11T00:00:00
Link: CVE-2024-46625
Vulnrichment
Updated: 2024-12-11T14:36:10.351Z
NVD
Status : Awaiting Analysis
Published: 2024-12-03T22:15:04.860
Modified: 2024-12-11T15:15:10.417
Link: CVE-2024-46625
Redhat
No data.