File Upload vulnerability in Xi'an Daxi Information technology OfficeWeb365 v.8.6.1.0 and v7.18.23.0 allows a remote attacker to execute arbitrary code via the pw/savedraw component.

Project Subscriptions

Vendors Products
Xian Daxi Information Technology Subscribe
Officeweb 365 Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 21 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Xian Daxi Information Technology
Xian Daxi Information Technology officeweb 365
Weaknesses CWE-94
CPEs cpe:2.3:a:xian_daxi_information_technology:officeweb_365:*:*:*:*:*:*:*:*
Vendors & Products Xian Daxi Information Technology
Xian Daxi Information Technology officeweb 365
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 19 Nov 2024 18:30:00 +0000


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-11-21T16:24:26.201Z

Reserved: 2024-10-08T00:00:00

Link: CVE-2024-48694

cve-icon Vulnrichment

Updated: 2024-11-21T16:24:07.996Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-19T19:15:08.140

Modified: 2024-11-21T17:15:20.110

Link: CVE-2024-48694

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses