An issue was discovered in GNU Savane v.3.13 and before, allows a remote attacker to execute arbitrary code and escalate privileges via a crafted file to the upload.php component.
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:LGnu Savane
APPGnu≤ 3.13
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCELPE
CWE
Related vulnerabilities
CVE-2024-27630HIGH7.5same product
Insecure Direct Object Reference (IDOR) in GNU Savane v.3.12 and before allows a remote attacker to delete arb...
CVE-2024-27632HIGH8.8same product
An issue in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via the form_id in th...
CVE-2024-27631MEDIUM6.0same product
Cross Site Request Forgery vulnerability in GNU Savane v.3.12 and before allows a remote attacker to escalate ...
CVE-2026-24061CRITICAL9.8⚠ KEVPL ✓same vendor
GNU Inetutils telnetd: ominięcie uwierzytelnienia przez zmienną USER
CVE-2014-7169CRITICAL9.8⚠ KEVPL ✓same vendor
GNU Bash — niekompletna łatka Shellshock umożliwia command injection (CVE-2014-7169)