9.8

CVE-2024-44849

Exploit
Qualitor up to 8.24 is vulnerable to Remote Code Execution (RCE) via Arbitrary File Upload in checkAcesso.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
QualitorQualitor Version8.20
QualitorQualitor Version8.24
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 46.3% 0.987
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

https://blog.extencil.me/information-security/cves/cve-2024-44849
Third Party Advisory
Exploit
https://github.com/extencil/CVE-2024-44849?tab=readme-ov-file
Third Party Advisory
https://www.qualitor.com.br/official-security-advisory-cve-2024-44849
Vendor Advisory