HIGH

CVE-2024-57968

Advantive Veracore 2025-02-03 CVSS v3.1
CVSS
8.8
KEV

Description

Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible during web browsing by other users). upload.aspx can be used for this.

Summary dbcve.org

Advantive VeraCore before 2024.4.2.1 contains an insecure file upload vulnerability in upload.aspx. Authenticated users can manipulate the upload path to place files into web-accessible directories, potentially enabling remote code execution if executable file types are uploaded.

Mitigation

Apply vendor patch 2024.4.2.1 or later. Until then, restrict upload functionality to non-web-accessible directories and validate upload paths server-side to prevent path traversal.

Proof of Concept

Weakness (CWE)

CWE-434 Unrestricted File Upload

EPSS Score

32.28%
Probability of exploitation in next 30 days
98.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE