PT-2024-25947 · Unknown · Xlang Openagents
Published
2024-05-05
·
Updated
2024-07-03
·
CVE-2024-34524
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
XLANG OpenAgents versions through fe73ac4
Description
The allowed file protection mechanism can be bypassed by using an incorrect file extension for the nature of the file content.
Recommendations
For versions through fe73ac4, consider restricting file uploads to only those with expected extensions to minimize the risk of exploitation until a patch is available.
Fix
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xlang Openagents