10
CVE-2024-0643
- EPSS 0.67%
- Veröffentlicht 17.01.2024 14:15:43
- Zuletzt bearbeitet 21.11.2024 08:47:03
- Quelle cve-coordination@incibe.es
- CVE-Watchlists
- Unerledigt
Unrestricted upload of dangerous file types in C21 Live Encoder and Live Mosaic
Unrestricted upload of dangerous file types in the C21 Live Encoder and Live Mosaic product, version 5.3. This vulnerability allows a remote attacker to upload different file extensions without any restrictions, resulting in a full system compromise.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cires21 ≫ Live Encoder Version5.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.67% | 0.471 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| cve-coordination@incibe.es | 10 | 3.9 | 6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-cires21-products