PT-2024-22371 · Unknown · Recrystallize Server

Paul Van Der Haas

·

Published

2024-04-08

·

Updated

2024-07-03

·

CVE-2024-28269

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ReCrystallize Server version 5.10.0.0
Description The issue allows administrators to upload files to the server without restrictions, leading to the potential upload of malicious files. This could result in Remote Code Execution.
Recommendations For ReCrystallize Server version 5.10.0.0, restrict file upload capabilities to prevent the upload of malicious files until a patch is available. As a temporary workaround, consider implementing strict validation and sanitization of uploaded files to minimize the risk of exploitation.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-28269

Affected Products

Recrystallize Server