HIGH
CVE-2024-57968
CVSS
8.8
KEV
Description
Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible during web browsing by other users). upload.aspx can be used for this.
Summary dbcve.org
Advantive VeraCore before 2024.4.2.1 contains an insecure file upload vulnerability in upload.aspx. Authenticated users can manipulate the upload path to place files into web-accessible directories, potentially enabling remote code execution if executable file types are uploaded.
Mitigation
Apply vendor patch 2024.4.2.1 or later. Until then, restrict upload functionality to non-web-accessible directories and validate upload paths server-side to prevent path traversal.
Weakness (CWE)
CWE-434
Unrestricted File Upload
EPSS Score
32.28%
Probability of exploitation in next 30 days
98.3th percentile
References
https://advantive.my.site.com/support/s/article/VeraCore-Release-Notes-2024-4-2-1
Permissions Required, Product, Release Notes
https://intezer.com/blog/research/xe-group-exploiting-zero-days/
Exploit, Technical Description, Third Party Advisory
https://www.solissecurity.com/en-us/insights/xe-group-from-credit-card-skimming-to-exploiting-zero-days/
Exploit, Technical Description, Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-57968
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.