HIGH

CVE-2024-7694

Teamt5 Threatsonar Anti Ransomware 2024-08-12 CVSS v3.1
CVSS
7.2
KEV

Description

ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious files, which can be used to execute arbitrary system command on the server.

Summary dbcve.org

ThreatSonar Anti-Ransomware from TeamT5 contains a file upload vulnerability where the application does not properly validate the content of uploaded files. An authenticated remote attacker with administrator privileges can upload malicious files containing arbitrary code, leading to command execution on the underlying server.

Mitigation

Implement strict file content validation (magic byte checking, file type verification) on all upload functions, restrict executable file extensions, and store uploaded files in a non-executable directory with proper access controls.

Weakness (CWE)

CWE-434 Unrestricted File Upload

EPSS Score

1.81%
Probability of exploitation in next 30 days
77.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE