PT-2024-22844 · Vvvebjs · Vvvebjs

Hebing123

·

Published

2024-03-21

·

Updated

2024-08-01

·

CVE-2024-29272

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions VvvebJs versions prior to 1.7.5
Description The issue allows unauthenticated remote attackers to execute arbitrary code and obtain sensitive information via the sanitizeFileName parameter in the "save.php" file. This enables remote attacks, posing a significant risk.
Recommendations For versions prior to 1.7.5, update VvvebJs to version 1.7.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the "save.php" file or disabling the sanitizeFileName parameter until a patch is applied.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-29272
GHSA-PMM3-68Q9-57JG

Affected Products

Vvvebjs