Back

CRITICAL

Ragic Enterprise Cloud Database - Arbitrary File Upload

Published Oct 15, 2024

Description

Enterprise Cloud Database from Ragic does not properly validate the file type for uploads. Attackers with regular privileges can upload a webshell and use it to execute arbitrary code on the remote server.

Affected products

Remediation

Vendor solution

Update to version 2024/08/08 09:45:25 or later.

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner twcert
Published Oct 15, 2024
Updated Oct 15, 2024
Reserved Oct 15, 2024
CISA Vulnrichment
Updated Oct 15, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner twcert
Published Oct 15, 2024
Updated Oct 15, 2024
Exploited since n/a
EUVD-2024-50264