Enterprise Cloud Database from Ragic does not properly validate the file type for uploads. Attackers with regular privileges can upload a webshell and use it to execute arbitrary code on the remote server.

Subscriptions

Vendors Products
Enterprise Cloud Database Subscribe

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-50264 Enterprise Cloud Database from Ragic does not properly validate the file type for uploads. Attackers with regular privileges can upload a webshell and use it to execute arbitrary code on the remote server.
Fixes

Solution

Update to version 2024/08/08 09:45:25 or later.


Workaround

No workaround given by the vendor.

History

Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00336}

epss

{'score': 0.00375}


Tue, 15 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Ragic
Ragic enterprise Cloud Database
CPEs cpe:2.3:a:ragic:enterprise_cloud_database:*:*:*:*:*:*:*:*
Vendors & Products Ragic
Ragic enterprise Cloud Database
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Oct 2024 08:30:00 +0000

Type Values Removed Values Added
Description Enterprise Cloud Database from Ragic does not properly validate the file type for uploads. Attackers with regular privileges can upload a webshell and use it to execute arbitrary code on the remote server.
Title Ragic Enterprise Cloud Database - Arbitrary File Upload
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2024-10-15T13:37:34.053Z

Reserved: 2024-10-15T06:58:05.293Z

Link: CVE-2024-9985

cve-icon Vulnrichment

Updated: 2024-10-15T13:37:27.440Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-15T09:15:04.693

Modified: 2024-10-16T22:02:08.117

Link: CVE-2024-9985

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses