PT-2024-35926 · Unknown · Wdesignkit

Tahu.Datar

·

Published

2024-12-06

·

Updated

2024-12-06

·

CVE-2024-53811

CVSS v3.1

6.6

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions WDesignkit versions 1.0.0 through 1.0.40
Description The issue allows for the unrestricted upload of files with dangerous types, enabling the upload of a web shell to a web server. This can be exploited to gain unauthorized access to the server.
Recommendations For versions 1.0.0 through 1.0.40, consider restricting file uploads to only allow safe file types until a patch is available. As a temporary workaround, restrict access to the file upload functionality to minimize the risk of exploitation.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-53811

Affected Products

Wdesignkit