A vulnerability classified as critical has been found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.0. This affects the function fileUpload of the file /admin/File/fileUpload. The manipulation of the argument file leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The affected product is known with different names like 07FLYCMS, 07FLY-CMS, and 07FlyCRM. It was not possible to reach out to the vendor before assigning a CVE due to a not working mail address.
History

Tue, 15 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Zero Takeoff
Zero Takeoff 07fly-cms
Zero Takeoff 07flycms
Zero Takeoff 07flycrm
CPEs cpe:2.3:a:zero_takeoff:07fly-cms:*:*:*:*:*:*:*:*
cpe:2.3:a:zero_takeoff:07flycms:*:*:*:*:*:*:*:*
cpe:2.3:a:zero_takeoff:07flycrm:*:*:*:*:*:*:*:*
Vendors & Products Zero Takeoff
Zero Takeoff 07fly-cms
Zero Takeoff 07flycms
Zero Takeoff 07flycrm
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Oct 2024 23:15:00 +0000

Type Values Removed Values Added
Description A vulnerability classified as critical has been found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.0. This affects the function fileUpload of the file /admin/File/fileUpload. The manipulation of the argument file leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The affected product is known with different names like 07FLYCMS, 07FLY-CMS, and 07FlyCRM. It was not possible to reach out to the vendor before assigning a CVE due to a not working mail address.
Title 07FLYCMS/07FLY-CMS/07FlyCRM fileUpload unrestricted upload
Weaknesses CWE-434
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:N/AC:L/Au:M/C:P/I:P/A:P'}

cvssV3_0

{'score': 4.7, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'}

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2024-10-12T23:00:06.275Z

Updated: 2024-10-15T14:38:20.692Z

Reserved: 2024-10-12T06:25:11.177Z

Link: CVE-2024-9903

cve-icon Vulnrichment

Updated: 2024-10-15T14:37:03.919Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-12T23:15:11.027

Modified: 2024-10-15T12:57:46.880

Link: CVE-2024-9903

cve-icon Redhat

No data.