← Retour aux CVEs
CVE-2024-57968
CRITICALCISA KEV9.9
Description
Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible during web browsing by other users). upload.aspx can be used for this.
Details CVE
Score CVSS v3.19.9
SeveriteCRITICAL
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisLOW
Interaction utilisateurNONE
Publie2/3/2025
Derniere modification11/4/2025
Sourcekev
Observations honeypot0
CISA KEV
FournisseurAdvantive
ProduitVeraCore
Nom vulnerabiliteAdvantive VeraCore Unrestricted File Upload Vulnerability
Date ajout KEV2025-03-10
Date limite remediation2025-03-31
Utilise dans ransomwareUnknown
Produits affectes
advantive:veracore
Faiblesses (CWE)
CWE-434CWE-434
References
https://www.solissecurity.com/en-us/insights/xe-group-from-credit-card-skimming-to-exploiting-zero-days/(cve@mitre.org)
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-57968(134c704f-9b21-4f2e-91b3-4a467353bcc0)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.