PT-2024-27781 · Mango Api+1 · Mango Api+1

Published

2024-10-25

·

Updated

2024-11-05

·

CVE-2024-37847

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MangoOS versions prior to 5.1.4 Mango API versions prior to 4.5.5
Description An arbitrary file upload issue allows attackers to execute arbitrary code via a crafted file.
Recommendations For MangoOS versions prior to 5.1.4, update to version 5.1.4 or later. For Mango API versions prior to 4.5.5, update to version 4.5.5 or later.

Exploit

Fix

Path traversal

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-37847

Affected Products

Mango Api
Mangoos