PT-2024-33468 · Unknown · Woostagram Connect

João Pedro S Alcântara

·

Published

2024-10-20

·

Updated

2024-10-24

·

CVE-2024-49327

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Woostagram Connect versions 1.0.0 through 1.0.2
Description The issue allows unrestricted upload of dangerous file types, which can lead to web server compromise by uploading a web shell. This can be exploited by uploading malicious files to the web server.
Recommendations Update to version 1.0.3 to fix the issue. As a temporary workaround, consider restricting file uploads to prevent potential exploitation until the update is applied.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-49327

Affected Products

Woostagram Connect