PT-2024-32952 · Unknown · Pdf Flipbook+1

Stealthcopter

·

Published

2024-10-16

·

Updated

2024-10-16

·

CVE-2024-48034

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Creates 3D Flipbook, PDF Flipbook versions 1.2 and earlier
Description The issue allows for the unrestricted upload of files with dangerous types, enabling the upload of a web shell to a web server. This can be exploited by uploading a malicious file, potentially leading to unauthorized access or control of the server.
Recommendations For versions 1.2 and earlier, consider disabling the file upload feature until a patch is available to prevent the upload of dangerous file types. Restrict access to the upload functionality to minimize the risk of exploitation. Avoid using the upload feature in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-48034

Affected Products

3D Flipbook
Pdf Flipbook