PT-2024-28918 · Unknown · Tmall Demo

Rabbit

·

Published

2024-07-15

·

Updated

2025-06-13

·

CVE-2024-40553

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Tmall demo version 2024.07.03
Description The issue allows for an arbitrary file upload through the uploadUserHeadImage component.
Recommendations For Tmall demo version 2024.07.03, consider disabling the uploadUserHeadImage component until a patch is available to prevent arbitrary file uploads.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-40553

Affected Products

Tmall Demo