PT-2024-2171 · Unknown · F-Logic Datacube3
0Xsamy
+3
·
Published
2024-02-20
·
Updated
2025-01-16
·
CVE-2024-25832
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
F-logic DataCube3 version 1.0
Description
The issue is related to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of a dangerous type by manipulating the filename extension. This could potentially enable a remote attacker to execute arbitrary code.
Recommendations
For F-logic DataCube3 version 1.0, consider restricting file uploads to only allow specific, safe file types until a patch is available. As a temporary workaround, disabling file upload functionality may help minimize the risk of exploitation.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
F-Logic Datacube3