HIGH🇵🇱 Wersja polska

CVE-2024-47655

CVSS 8.6v4.0pub. 2024-10-04upd. 2024-10-16

This vulnerability exists in the Shilpi Client Dashboard due to improper validation of files being uploaded other than the specified extension. An authenticated remote attacker could exploit this vulnerability by uploading malicious file, which could lead to remote code execution on targeted application.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Shilpisoft Client Dashboard

    APP
    Shilpisoft
    < 9.7.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2024-47656CRITICAL9.3PL ✓same product

Brak ograniczeń prób logowania w Shilpi Client Dashboard (brute force)

CVE-2024-47652HIGH7.6same product

This vulnerability exists in Shilpi Client Dashboard due to implementation of inadequate authentication mechan...

CVE-2024-47653HIGH7.1same product

This vulnerability exists in Shilpi Client Dashboard due to lack of authorization for modification and cancell...

CVE-2024-47654HIGH7.1same product

This vulnerability exists in Shilpi Client Dashboard due to lack of rate limiting and Captcha protection for O...

CVE-2024-47657HIGH7.1same vendor

This vulnerability exists in the Shilpi Net Back Office due to improper access controls on certain API endpoin...