Description
Vulnerability in the Scriptcase application version 9.4.019, which involves the arbitrary upload of a file via /scriptcase/devel/lib/third/jquery_plugin/jQuery-File-Upload/server/php/ via a POST request. An attacker could upload malicious files to the server due to the application not properly verifying user input.
Published: 2024-09-24
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

The vulnerability has been fixed in the latest version.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-49497 Vulnerability in the Scriptcase application version 9.4.019, which involves the arbitrary upload of a file via /scriptcase/devel/lib/third/jquery_plugin/jQuery-File-Upload/server/php/ via a POST request. An attacker could upload malicious files to the server due to the application not properly verifying user input.
History

Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00185}

epss

{'score': 0.00201}


Tue, 24 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Scriptcase
Scriptcase scriptcase
CPEs cpe:2.3:a:scriptcase:scriptcase:9.4.019:*:*:*:*:*:*:*
Vendors & Products Scriptcase
Scriptcase scriptcase
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 24 Sep 2024 12:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Scriptcase application version 9.4.019, which involves the arbitrary upload of a file via /scriptcase/devel/lib/third/jquery_plugin/jQuery-File-Upload/server/php/ via a POST request. An attacker could upload malicious files to the server due to the application not properly verifying user input.
Title Unrestricted Upload of File with Dangerous Type vulnerability on Scriptcase
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Scriptcase Scriptcase
cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-09-24T13:28:36.727Z

Reserved: 2024-09-17T09:43:47.523Z

Link: CVE-2024-8940

cve-icon Vulnrichment

Updated: 2024-09-24T13:28:26.544Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-25T01:15:48.087

Modified: 2024-10-01T17:21:01.550

Link: CVE-2024-8940

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses