PT-2024-31512 · Byob · Byob

Chebuya

·

Published

2024-08-25

·

Updated

2024-10-15

·

CVE-2024-45256

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BYOB (Build Your Own Botnet) version 2.0
Description An arbitrary file write issue in the exfiltration endpoint allows attackers to overwrite SQLite databases and bypass authentication via an unauthenticated HTTP request with a crafted parameter. This occurs in file add in api/files/routes.py.
Recommendations As a temporary workaround, consider disabling the file add function in api/files/routes.py until a patch is available. Restrict access to the exfiltration endpoint to minimize the risk of exploitation. Avoid using crafted parameters in unauthenticated HTTP requests to the affected endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-45256

Affected Products

Byob