PT-2024-27748 · Ai3 · Ai3 Qbibot

Huding

·

Published

2024-04-14

·

Updated

2024-04-15

·

CVE-2024-3778

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ai3 QbiBot versions prior to 8.0.4
Description The issue concerns the file upload functionality, which does not properly restrict the types of files that can be uploaded. This allows remote attackers with administrator privileges to upload files containing malicious code.
Recommendations For Ai3 QbiBot versions prior to 8.0.4, upgrade to a patched version and review uploaded files to mitigate the risk. As a temporary workaround, consider restricting access to the file upload functionality to minimize the risk of exploitation.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-3778

Affected Products

Ai3 Qbibot