PT-2026-7656 · Cipplanner · Cipace

Published

2026-02-11

·

Updated

2026-02-18

·

CVE-2024-50620

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CIPPlanner CIPAce versions prior to 9.17
Description The software contains flaws related to unrestricted file uploads with dangerous file types in the rich text editor and document management components. A user with authorization can upload executable files through the rich text editor when inserting images and through the document management page when uploading files. If these executables are not stored in a shared directory or if the storage directory has execute permissions, they can be executed.
Recommendations Update to version 9.17 or later.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-50620

Affected Products

Cipace