PT-2026-7656 · Cipplanner · Cipace
Published
2026-02-11
·
Updated
2026-02-18
·
CVE-2024-50620
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CIPPlanner CIPAce versions prior to 9.17
Description
The software contains flaws related to unrestricted file uploads with dangerous file types in the rich text editor and document management components. A user with authorization can upload executable files through the rich text editor when inserting images and through the document management page when uploading files. If these executables are not stored in a shared directory or if the storage directory has execute permissions, they can be executed.
Recommendations
Update to version 9.17 or later.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cipace