PT-2024-33467 · Unknown · Vasilis Kerasiotis Affiliator

João Pedro S Alcântara

·

Published

2024-10-20

·

Updated

2024-10-24

·

CVE-2024-49326

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Vasilis Kerasiotis Affiliator versions 2.1.3 and earlier
Description The issue allows an attacker to upload a web shell to a web server due to an unrestricted file upload vulnerability. This enables the attacker to execute malicious code on the server.
Recommendations For versions 2.1.3 and earlier, update to version 2.1.4 to patch this critical vulnerability. As a temporary workaround, consider restricting file uploads to prevent potential exploitation until the update can be applied.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-49326

Affected Products

Vasilis Kerasiotis Affiliator