Back

CRITICAL

An issue in aliyundrive-webdav v.2.3.3 and before allows a remote attacker to execute arbitrary code via a crafted payload to the sid parameter in the action_query_qrcode component

Published Mar 29, 2024

Description

An issue in aliyundrive-webdav v.2.3.3 and before allows a remote attacker to execute arbitrary code via a crafted payload to the sid parameter in the action_query_qrcode component.

Affected products

Remediation

No remediation recorded yet.

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 29, 2024
Updated Jul 9, 2026
Reserved Mar 19, 2024
CISA Vulnrichment
Updated Mar 29, 2024
NVD
Status Deferred
Modified Jul 9, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner mitre
Published Mar 29, 2024
Updated Jul 9, 2026
Exploited since n/a
EUVD-2024-0851 GHSA-73V2-RXQP-7Q4F