PT-2024-26246 · Unknown · R-Pan-Scaffolding

Published

2024-05-15

·

Updated

2024-08-29

·

CVE-2024-34913

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions r-pan-scaffolding versions 5.0 and below
Description The issue allows attackers to execute arbitrary code via uploading a crafted PDF file. This is achieved through an arbitrary file upload vulnerability.
Recommendations For versions 5.0 and below, consider restricting access to file upload functionality until a fix is available. As a temporary workaround, avoid using the file upload feature in r-pan-scaffolding until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-34913

Affected Products

R-Pan-Scaffolding