PT-2024-30023 · Erp · Erp

Topsky979

·

Published

2024-08-20

·

Updated

2024-08-21

·

CVE-2024-42563

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ERP commit 44bd04
Description An arbitrary file upload vulnerability allows attackers to execute arbitrary code via uploading a crafted HTML file.
Recommendations For ERP commit 44bd04, consider restricting the upload functionality to prevent the execution of arbitrary code until a patch is available. As a temporary workaround, restrict access to the file upload feature to minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-42563

Affected Products

Erp