PT-2024-21065 · Unknown · Pandaxgo Pandax

Linyz-Tel

·

Published

2024-03-17

·

Updated

2024-05-17

·

CVE-2024-2565

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PandaXGO PandaX up to 20240310
Description A critical issue has been found in the File Extension Handler component, specifically in the /apps/system/router/upload.go file. The manipulation of the file argument leads to unrestricted upload. This issue can be exploited remotely. The exploit has been disclosed to the public.
Recommendations For PandaXGO PandaX up to 20240310, as a temporary workaround, consider restricting access to the upload functionality in the /apps/system/router/upload.go file until a patch is available. Avoid using the file argument in the affected component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-2565

Affected Products

Pandaxgo Pandax