Vulnerability Description
A file upload bypass vulnerability exists in SOPlanning 1.53.00, specifically in /process/upload.php. This vulnerability allows remote attackers to bypass upload restrictions and potentially achieve remote code execution by uploading malicious files.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Soplanning | Soplanning | 1.53.00 |
Related Weaknesses (CWE)
References
- https://themcsam.github.io/posts/so-planing-vulnerabilities/#arbitrary-file-uploExploit
- https://themcsam.github.io/posts/so-planing-vulnerabilities/#arbitrary-file-uploExploit
FAQ
What is CVE-2024-57169?
CVE-2024-57169 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A file upload bypass vulnerability exists in SOPlanning 1.53.00, specifically in /process/upload.php. This vulnerability allows remote attackers to bypass upload restrictions and potentially achieve r...
How severe is CVE-2024-57169?
CVE-2024-57169 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-57169?
Check the references section above for vendor advisories and patch information. Affected products include: Soplanning Soplanning.