216.73.216.233

CVE-2024-11984

· Published 19/12/2024 04:15 · Modified 20/12/2024 18:15

Labels: CVE-2024-11984 2024-12-19[email protected]CVE-2024-11984CWE-434

Essential information

Published
19/12/2024 04:15
Modified
20/12/2024 18:15
Author
Creator
CVSS
8.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

A unrestricted upload of file with dangerous type vulnerability in epaper draft function in Corporate Training Management System before 10.13 allows remote authenticated users to bypass file upload restrictions and perform arbitrary system commands with SYSTEM privilege via a crafted ZIP file.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

References