Vulnerability in the Scriptcase application version 9.4.019, which involves the arbitrary upload of a file via /scriptcase/devel/lib/third/jquery_plugin/jQuery-File-Upload/server/php/ via a POST request. An attacker could upload malicious files to the server due to the application not properly verifying user input.
History

Tue, 24 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Scriptcase
Scriptcase scriptcase
CPEs cpe:2.3:a:scriptcase:scriptcase:9.4.019:*:*:*:*:*:*:*
Vendors & Products Scriptcase
Scriptcase scriptcase
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 24 Sep 2024 12:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Scriptcase application version 9.4.019, which involves the arbitrary upload of a file via /scriptcase/devel/lib/third/jquery_plugin/jQuery-File-Upload/server/php/ via a POST request. An attacker could upload malicious files to the server due to the application not properly verifying user input.
Title Unrestricted Upload of File with Dangerous Type vulnerability on Scriptcase
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2024-09-24T11:48:36.160Z

Updated: 2024-09-24T13:28:36.727Z

Reserved: 2024-09-17T09:43:47.523Z

Link: CVE-2024-8940

cve-icon Vulnrichment

Updated: 2024-09-24T13:28:26.544Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-25T01:15:48.087

Modified: 2024-09-26T13:32:02.803

Link: CVE-2024-8940

cve-icon Redhat

No data.