Show plain JSON{"dataType": "CVE_RECORD", "dataVersion": "5.1", "cveMetadata": {"cveId": "CVE-2024-11018", "assignerOrgId": "cded6c7f-6ce5-4948-8f87-aa7a3bbb6b0e", "state": "PUBLISHED", "assignerShortName": "twcert", "dateReserved": "2024-11-08T05:54:42.229Z", "datePublished": "2024-11-11T07:02:59.316Z", "dateUpdated": "2024-11-11T16:02:46.183Z"}, "containers": {"cna": {"affected": [{"defaultStatus": "unaffected", "product": "Webopac", "vendor": "Grand Vice info", "versions": [{"lessThan": "6.5.1", "status": "affected", "version": "6", "versionType": "custom"}, {"lessThan": "7.2.3", "status": "affected", "version": "7", "versionType": "custom"}]}], "datePublic": "2024-11-11T06:55:00.000Z", "descriptions": [{"lang": "en", "supportingMedia": [{"base64": false, "type": "text/html", "value": "Webopac from Grand Vice info does not properly validate uploaded file types, allowing unauthenticated remote attackers to upload and execute webshells, which could lead to arbitrary code execution on the server."}], "value": "Webopac from Grand Vice info does not properly validate uploaded file types, allowing unauthenticated remote attackers to upload and execute webshells, which could lead to arbitrary code execution on the server."}], "impacts": [{"capecId": "CAPEC-650", "descriptions": [{"lang": "en", "value": "CAPEC-650 Upload a Web Shell to a Web Server"}]}], "metrics": [{"cvssV3_1": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 9.8, "baseSeverity": "CRITICAL", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1"}, "format": "CVSS", "scenarios": [{"lang": "en", "value": "GENERAL"}]}], "problemTypes": [{"descriptions": [{"cweId": "CWE-434", "description": "CWE-434 Unrestricted Upload of File with Dangerous Type", "lang": "en", "type": "CWE"}]}], "providerMetadata": {"orgId": "cded6c7f-6ce5-4948-8f87-aa7a3bbb6b0e", "shortName": "twcert", "dateUpdated": "2024-11-11T07:10:24.847Z"}, "references": [{"tags": ["vendor-advisory"], "url": "https://www.twcert.org.tw/tw/cp-132-8213-3413b-1.html"}, {"tags": ["vendor-advisory"], "url": "https://www.twcert.org.tw/en/cp-139-8214-64fa2-2.html"}], "solutions": [{"lang": "en", "supportingMedia": [{"base64": false, "type": "text/html", "value": "<span style=\"background-color: rgb(255, 255, 255);\">Update Webopac 6 to version 6.5.1 or later</span><br><span style=\"background-color: rgb(255, 255, 255);\">Update Webopac 7 to version 7.2.3 or later.</span>\n\n<br>"}], "value": "Update Webopac 6 to version 6.5.1 or later\nUpdate Webopac 7 to version 7.2.3 or later."}], "source": {"advisory": "TVN-202411003", "discovery": "EXTERNAL"}, "title": "Grand Vice info Webopac - Arbitrary File Upload", "x_generator": {"engine": "Vulnogram 0.2.0"}}, "adp": [{"affected": [{"vendor": "vice", "product": "webopac", "cpes": ["cpe:2.3:a:vice:webopac:*:*:*:*:*:*:*:*"], "defaultStatus": "unaffected", "versions": [{"version": "6.0", "status": "affected", "lessThan": "6.5.1", "versionType": "custom"}, {"version": "7.0", "status": "affected", "lessThan": "7.2.3", "versionType": "custom"}]}], "metrics": [{"other": {"type": "ssvc", "content": {"timestamp": "2024-11-11T16:02:41.917551Z", "id": "CVE-2024-11018", "options": [{"Exploitation": "none"}, {"Automatable": "yes"}, {"Technical Impact": "total"}], "role": "CISA Coordinator", "version": "2.0.3"}}}], "title": "CISA ADP Vulnrichment", "providerMetadata": {"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-11-11T16:02:46.183Z"}}]}}