Unrestricted Upload of File with Dangerous Type vulnerability on Scriptcase
Published Sep 24, 2024
10.0
CRITICALCVSS 3.1
EPSS 0.55%
Description
Vulnerability in the Scriptcase application version 9.4.019, which involves the arbitrary upload of a file via /scriptcase/devel/lib/third/jquery_plugin/jQuery-File-Upload/server/php/ via a POST request. An attacker could upload malicious files to the server due to the application not properly verifying user input.
Affected products
-
- Version 9.4.019StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Scriptcase | Scriptcase | unaffected |
|
- 9.4.019
-
- Version 9.4.019StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Scriptcase | Scriptcase | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
The vulnerability has been fixed in the latest version.
References (1)
- https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-scriptcase Third Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-scriptcase | Third Party Advisory |
Change history (0)
No recorded changes yet.