PT-2024-35165 · Unknown · Common-User-Management

D3Sca

·

Published

2024-11-14

·

Updated

2025-04-15

·

CVE-2024-52302

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions common-user-management (affected versions not specified)
Description The issue concerns a critical security vulnerability in the application endpoint /api/v1/customer/profile-picture, which allows file uploads without proper validation or restrictions. This enables attackers to upload malicious files, potentially leading to Remote Code Execution (RCE).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-52302
GHSA-RHCQ-44G3-5XCX

Affected Products

Common-User-Management