PT-2024-17382 · Unknown · Corporate Training Management System
Yen Chun Shen
·
Published
2024-12-19
·
Updated
2024-12-24
·
CVE-2024-11984
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Corporate Training Management System versions prior to 10.13
Description
A vulnerability in the epaper draft function of the Corporate Training Management System allows remote authenticated users to bypass file upload restrictions and execute arbitrary system commands with SYSTEM privilege via a crafted ZIP file. This issue is related to an unrestricted upload of files with dangerous types.
Recommendations
For versions prior to 10.13, update to version 10.13 or later to resolve the issue. As a temporary workaround, consider restricting access to the epaper draft function to minimize the risk of exploitation. Additionally, avoid using the epaper draft function until the issue is resolved.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Corporate Training Management System