216.73.217.22

CVE-2024-45256

· Published 26/08/2024 07:15 · Modified 26/08/2024 13:35

Labels: CVE-2024-45256 2024-08-26CVE-2024-45256CWE-22[email protected]

Essential information

Published
26/08/2024 07:15
Modified
26/08/2024 13:35
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

An arbitrary file write issue in the exfiltration endpoint in BYOB (Build Your Own Botnet) 2.0 allows attackers to overwrite SQLite databases and bypass authentication via an unauthenticated HTTP request with a crafted parameter. This occurs in file_add in api/files/routes.py.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

References