← Volver a CVEs
CVE-2024-45136
HIGH7.8
Descripcion
InCopy versions 19.4, 18.5.3 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution by an attacker. An attacker could exploit this vulnerability by uploading a malicious file which can then be executed on the server. Exploitation of this issue requires user interaction.
Detalles CVE
Puntuacion CVSS v3.17.8
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vector de ataqueLOCAL
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioREQUIRED
Publicado10/9/2024
Ultima modificacion10/18/2024
Fuentenvd
Avistamientos honeypot0
Productos afectados
adobe:incopyapple:macosmicrosoft:windows
Debilidades (CWE)
CWE-434
Referencias
https://helpx.adobe.com/security/products/incopy/apsb24-79.html(psirt@adobe.com)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.