PT-2024-26563 · O2Oa · O2Oa

Lianghao-Chu

·

Published

2024-05-24

·

Updated

2025-09-30

·

CVE-2024-35591

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions O2OA version 8.3.8
Description The issue allows attackers to execute arbitrary code by uploading a crafted PDF file, exploiting an arbitrary file upload vulnerability.
Recommendations For O2OA version 8.3.8, consider restricting file uploads to prevent exploitation until a patch is available. As a temporary workaround, limit the types of files that can be uploaded to minimize the risk.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-35591

Affected Products

O2Oa