PT-2024-33605 · Unknown · Portfolleo

Stealthcopter

·

Published

2024-10-23

·

Updated

2024-10-25

·

CVE-2024-49653

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Portfolleo versions 1.2 and earlier
Description The issue allows for the unrestricted upload of files with dangerous types, enabling an attacker to upload a web shell to a web server.
Recommendations For Portfolleo versions 1.2 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-49653

Affected Products

Portfolleo