Overview
- Description
- Webopac from Grand Vice info does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload and execute webshells, which could lead to arbitrary code execution on the server.
- Source
- twcert@cert.org.tw
- NVD status
- Undergoing Analysis
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
Weaknesses
- twcert@cert.org.tw
- CWE-434
Social media
- Hype score
- Not currently trending
CVE-2024-11017 Webopac from Grand Vice info does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload and execute webshells, which … https://t.co/UoQYdHOxVY
@CVEnew
11 Nov 2024
35 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[CVE-2024-11017: HIGH] Grand Vice info's Webopac system has a cyber security vulnerability where attackers can upload and run webshells, potentially leading to arbitrary code execution. #cybersecurity#cybersecurity,#vulnerability https://t.co/3aK9VFKpeD https://t.co/Jlg0n3gCP6
@CveFindCom
11 Nov 2024
33 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes