PT-2024-38953 · Unknown · Hfo4 Shudong-Share

Xmg404

·

Published

2024-08-30

·

Updated

2024-09-25

·

CVE-2024-8338

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: HFO4 shudong-share version 2.4.7
Description: A critical vulnerability was found in the file /includes/fileReceive.php of the component File Extension Handler. The manipulation of the file argument leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This issue only affects products that are no longer supported by the maintainer.
Recommendations: As a temporary workaround, consider disabling the file upload functionality in the /includes/fileReceive.php file until a patch is available. Restrict access to the File Extension Handler component to minimize the risk of exploitation. Avoid using the file argument in the affected functionality until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-8338

Affected Products

Hfo4 Shudong-Share