PT-2024-21997 · Leantime · Leantime

Bruno Menna

·

Published

2024-04-03

·

Updated

2024-08-28

·

CVE-2024-27705

CVSS v3.1

7.6

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions Leantime version 3.0.6
Description The issue allows attackers to execute arbitrary code via the upload of a crafted PDF file to the "files/browse" endpoint. This enables the execution of malicious scripts, potentially leading to unauthorized access or data manipulation.
Recommendations For Leantime version 3.0.6, consider disabling the file upload feature to the "files/browse" endpoint until a patch is available. Restrict access to this endpoint to minimize the risk of exploitation. Avoid using the file upload feature in this version until the issue is resolved.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-27705

Affected Products

Leantime