PT-2024-34365 · Digi · Digi Connectport Lts
Published
2024-12-09
·
Updated
2025-06-27
·
CVE-2024-50625
CVSS v3.1
8.0
High
| Vector | AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Digi ConnectPort LTS versions prior to 1.4.12
Description:
A vulnerability in the file upload handling of a web application allows manipulation of file paths via POST requests to API endpoints such as
/file/upload. This can lead to arbitrary file uploads within specific directories, potentially enabling privilege escalation when combined with other vulnerabilities. The file path variable can be manipulated to achieve this.Recommendations:
For versions prior to 1.4.12, update to version 1.4.12 or later to resolve the issue. As a temporary workaround, consider restricting access to the file upload functionality to minimize the risk of exploitation. Avoid using the
file path variable in the affected API endpoint until the issue is resolved.Fix
LPE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Digi Connectport Lts