PT-2024-34304 · Unknown · Stacks Mobile App Builder

Stealthcopter

·

Published

2024-11-04

·

Updated

2024-11-06

·

CVE-2024-50527

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Stacks Mobile App Builder versions n/a through 5.2.3
Description: The issue allows the unrestricted upload of files with dangerous types, enabling attackers to upload malicious web shells to servers. This can lead to significant security risks. The estimated number of potentially affected devices worldwide is not specified. There is no information provided about real-world incidents where this issue was exploited.
Recommendations: For versions n/a through 5.2.3, consider disabling the file upload feature until a patch is available. Restrict access to the web server to minimize the risk of exploitation. Avoid using the vulnerable file upload functionality in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-50527

Affected Products

Stacks Mobile App Builder