PT-2024-20995 · Ruvaroa · Ruvaroa
Mr-Xn
·
Published
2024-05-08
·
Updated
2024-07-03
·
CVE-2024-25533
CVSS v3.1
9.4
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
RuvarOA versions 6.01 through 12.01
Description
Error messages in RuvarOA were discovered to leak the physical path of the website, specifically at the /WorkFlow/OfficeFileUpdate.aspx endpoint. This issue can allow attackers to write files to the server or execute arbitrary commands via crafted SQL statements.
Recommendations
For versions 6.01 through 12.01, consider restricting access to the /WorkFlow/OfficeFileUpdate.aspx endpoint until a patch is available. As a temporary workaround, avoid using crafted SQL statements that could exploit this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ruvaroa