PT-2024-24187 · Shibang Communications · Shibang Communications Co.

Published

2024-04-16

·

Updated

2024-09-06

·

CVE-2024-31680

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Shibang Communications Co., Ltd. IP network intercom broadcasting system version 1.0
Description The issue allows a local attacker to execute arbitrary code via the my parser.php component. This is a result of a File Upload vulnerability in the system.
Recommendations For version 1.0, consider disabling the my parser.php component until a patch is available to prevent arbitrary code execution. Restrict access to the component to minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-31680

Affected Products

Shibang Communications Co.