PT-2024-34610 · Omegat · Omegat

Published

2024-11-21

·

Updated

2024-12-04

·

CVE-2024-51366

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OmegaT version 6.0.1
Description The issue allows attackers to execute arbitrary code via uploading a crafted .conf file, exploiting an arbitrary file upload vulnerability in the component RoamingOmega.
Recommendations For OmegaT version 6.0.1, consider restricting access to the RoamingOmega component to minimize the risk of exploitation until a patch is available. Avoid uploading unverified .conf files to prevent potential code execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-51366

Affected Products

Omegat