A unrestricted upload of file with dangerous type vulnerability in epaper draft function in Corporate Training Management System before 10.13 allows remote authenticated users to bypass file upload restrictions and perform arbitrary system commands with SYSTEM privilege via a crafted ZIP file.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://zuso.ai/advisory/za-2024-10 |
History
Fri, 20 Dec 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Thu, 19 Dec 2024 04:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A unrestricted upload of file with dangerous type vulnerability in epaper draft function in Corporate Training Management System before 10.13 allows remote authenticated users to bypass file upload restrictions and perform arbitrary system commands with SYSTEM privilege via a crafted ZIP file. | |
Title | SUNNET Corporate Training Management System - Unrestricted Upload of File with Dangerous Type | |
Weaknesses | CWE-434 | |
References |
| |
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: ZUSO ART
Published: 2024-12-19T04:01:05.989Z
Updated: 2024-12-20T18:01:19.504Z
Reserved: 2024-11-29T07:10:52.536Z
Link: CVE-2024-11984
Vulnrichment
Updated: 2024-12-20T18:01:01.433Z
NVD
Status : Received
Published: 2024-12-19T04:15:05.127
Modified: 2024-12-20T18:15:26.703
Link: CVE-2024-11984
Redhat
No data.