PT-2025-9700 · Softwarex · Softwarex
CVE-2025-24494
·
Publicado
2025-03-04
·
Atualizado
2025-04-02
CVSS v3.1
7.2
Alta
| Vetor | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SoftwareX versions prior to 6.7.0
Description
The issue allows for path traversal, which may enable remote code execution using a privileged account, requiring a device admin account. This cannot be performed by a regular user. In combination with the 'Upload' functionality, it could be used to execute an arbitrary script or possibly an uploaded binary.
Recommendations
For versions prior to 6.7.0, update to Version 6.7.0, released on 20-Oct-24, to resolve the issue. As a temporary workaround, consider restricting the use of the 'Upload' functionality until the update is applied.
Correção
RCE
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Softwarex