PT-2024-34194 · Unknown · Adirectory
Stealthcopter
·
Published
2024-10-29
·
Updated
2024-10-29
·
CVE-2024-50420
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
aDirectory versions n/a through 1.3
Description:
The issue allows for the unrestricted upload of files with dangerous types to a web server, potentially enabling the upload of a web shell. This could lead to unauthorized access and control of the server.
Recommendations:
For versions n/a through 1.3, restrict or disable file upload functionality until a proper fix is implemented to validate and sanitize uploaded files, preventing the upload of dangerous file types.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Adirectory