InCopy versions 19.4, 18.5.3 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution by an attacker. An attacker could exploit this vulnerability by uploading a malicious file which can then be executed on the server. Exploitation of this issue requires user interaction.
                
            Metrics
Affected Vendors & Products
References
        History
                    Fri, 18 Oct 2024 14:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Apple
         Apple macos Microsoft Microsoft windows  | 
|
| CPEs | cpe:2.3:a:adobe:incopy:*:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*  | 
|
| Vendors & Products | 
        
        Apple
         Apple macos Microsoft Microsoft windows  | 
Wed, 09 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Adobe
         Adobe incopy  | 
|
| CPEs | cpe:2.3:a:adobe:incopy:-:*:*:*:*:*:*:* | |
| Vendors & Products | 
        
        Adobe
         Adobe incopy  | 
|
| Metrics | 
        
        ssvc
         
  | 
Wed, 09 Oct 2024 14:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | InCopy versions 19.4, 18.5.3 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution by an attacker. An attacker could exploit this vulnerability by uploading a malicious file which can then be executed on the server. Exploitation of this issue requires user interaction. | |
| Title | InCopy | Unrestricted Upload of File with Dangerous Type (CWE-434) | |
| Weaknesses | CWE-434 | |
| References | 
         | |
| Metrics | 
        
        cvssV3_1
         
  | 
Status: PUBLISHED
Assigner: adobe
Published: 2024-10-09T14:05:03.366Z
Updated: 2024-10-09T14:37:20.156Z
Reserved: 2024-08-21T23:00:59.349Z
Link: CVE-2024-45136
Updated: 2024-10-09T14:37:15.519Z
Status : Analyzed
Published: 2024-10-09T15:15:13.163
Modified: 2024-10-18T14:20:49.137
Link: CVE-2024-45136
No data.
ReportizFlow