PT-2024-16043 · Unknown · Wfh45678 Radar

Buxiaoding

·

Published

2024-10-18

·

Updated

2024-10-30

·

CVE-2024-10120

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions wfh45678 Radar versions up to 1.0.8
Description A critical issue has been found in the software, affecting unknown code in the file /services/v1/common/upload. The manipulation of the file argument leads to unrestricted upload. This can be initiated remotely. The issue may be used by attackers to upload malicious files.
Recommendations For versions up to 1.0.8, patch immediately and monitor for exploitation attempts. As a temporary workaround, consider restricting access to the /services/v1/common/upload endpoint until a patch is available. Avoid using the file argument in the affected API endpoint until the issue is resolved.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-10120

Affected Products

Wfh45678 Radar