This vulnerability exists in the Shilpi Client Dashboard due to improper validation of files being uploaded other than the specified extension. An authenticated remote attacker could exploit this vulnerability by uploading malicious file, which could lead to remote code execution on targeted application.
History

Wed, 16 Oct 2024 15:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Fri, 04 Oct 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Shilpisoft
Shilpisoft client Dashboard
CPEs cpe:2.3:a:shilpisoft:client_dashboard:*:*:*:*:*:*:*:*
Vendors & Products Shilpisoft
Shilpisoft client Dashboard
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 04 Oct 2024 12:30:00 +0000

Type Values Removed Values Added
Description This vulnerability exists in the Shilpi Client Dashboard due to improper validation of files being uploaded other than the specified extension. An authenticated remote attacker could exploit this vulnerability by uploading malicious file, which could lead to remote code execution on targeted application.
Title Unrestricted File Upload Vulnerability
Weaknesses CWE-434
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-In

Published: 2024-10-04T12:21:07.405Z

Updated: 2024-10-04T13:40:16.465Z

Reserved: 2024-09-30T11:42:54.095Z

Link: CVE-2024-47655

cve-icon Vulnrichment

Updated: 2024-10-04T13:40:11.436Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-04T13:15:11.797

Modified: 2024-10-16T15:26:15.350

Link: CVE-2024-47655

cve-icon Redhat

No data.