A unrestricted upload of file with dangerous type vulnerability in epaper draft function in Corporate Training Management System before 10.13 allows remote authenticated users to bypass file upload restrictions and perform arbitrary system commands with SYSTEM privilege via a crafted ZIP file.
References
History

Fri, 20 Dec 2024 18:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 19 Dec 2024 04:15:00 +0000

Type Values Removed Values Added
Description A unrestricted upload of file with dangerous type vulnerability in epaper draft function in Corporate Training Management System before 10.13 allows remote authenticated users to bypass file upload restrictions and perform arbitrary system commands with SYSTEM privilege via a crafted ZIP file.
Title SUNNET Corporate Training Management System - Unrestricted Upload of File with Dangerous Type
Weaknesses CWE-434
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ZUSO ART

Published: 2024-12-19T04:01:05.989Z

Updated: 2024-12-20T18:01:19.504Z

Reserved: 2024-11-29T07:10:52.536Z

Link: CVE-2024-11984

cve-icon Vulnrichment

Updated: 2024-12-20T18:01:01.433Z

cve-icon NVD

Status : Received

Published: 2024-12-19T04:15:05.127

Modified: 2024-12-20T18:15:26.703

Link: CVE-2024-11984

cve-icon Redhat

No data.