A vulnerability classified as critical was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.0. This vulnerability affects the function pictureUpload of the file /admin/File/pictureUpload. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The affected product is known with different names like 07FLYCMS, 07FLY-CMS, and 07FlyCRM. It was not possible to reach out to the vendor before assigning a CVE due to a not working mail address.
History

Tue, 15 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Zero Takeoff
Zero Takeoff 07fly-cms
Zero Takeoff 07flycms
Zero Takeoff 07flycrm
CPEs cpe:2.3:a:zero_takeoff:07fly-cms:*:*:*:*:*:*:*:*
cpe:2.3:a:zero_takeoff:07flycms:*:*:*:*:*:*:*:*
cpe:2.3:a:zero_takeoff:07flycrm:*:*:*:*:*:*:*:*
Vendors & Products Zero Takeoff
Zero Takeoff 07fly-cms
Zero Takeoff 07flycms
Zero Takeoff 07flycrm
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Oct 2024 01:45:00 +0000

Type Values Removed Values Added
Description A vulnerability classified as critical was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.0. This vulnerability affects the function pictureUpload of the file /admin/File/pictureUpload. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The affected product is known with different names like 07FLYCMS, 07FLY-CMS, and 07FlyCRM. It was not possible to reach out to the vendor before assigning a CVE due to a not working mail address.
Title 07FLYCMS/07FLY-CMS/07FlyCRM pictureUpload unrestricted upload
Weaknesses CWE-434
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:N/AC:L/Au:M/C:P/I:P/A:P'}

cvssV3_0

{'score': 4.7, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'}

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2024-10-13T01:31:04.358Z

Updated: 2024-10-15T14:28:47.424Z

Reserved: 2024-10-12T06:25:13.837Z

Link: CVE-2024-9904

cve-icon Vulnrichment

Updated: 2024-10-15T14:28:37.799Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-13T02:15:15.257

Modified: 2024-10-15T12:57:46.880

Link: CVE-2024-9904

cve-icon Redhat

No data.