PT-2025-3677 · Advantive · Advantive Veracore

Published

2024-11-13

·

Updated

2025-03-21

·

CVE-2024-57968

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Advantive VeraCore versions prior to 2024.4.2.1
Description The issue allows remote authenticated users to upload files to unintended folders, such as those accessible during web browsing by other users. The "upload.aspx" endpoint can be used for this purpose. The XE Group has been exploiting this issue to target supply chains, dropping reverse shells, exfiltrating files, and modifying data. This exploit has been used in real-world attacks, with the group shifting from credit card data theft to more sophisticated supply chain attacks.
Recommendations For Advantive VeraCore versions prior to 2024.4.2.1, consider disabling the upload feature from the application as a temporary workaround until a patch is available. Restrict access to the "upload.aspx" endpoint to minimize the risk of exploitation. Additionally, removing the upload feature from the application can help mitigate the risk, as seen in the temporary fix released for on-prem customers.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-07171
CVE-2024-57968

Affected Products

Advantive Veracore