CVE-2024-28698

Published Jul 22, 2024

Last updated 3 months ago

Insights

Analysis from the Intruder Security Team
Published Oct 15, 2024

This vulnerability affects applications using the CSLA.NET framework. It allows an attacker to execute code on the server if they are also able to upload a file to the server to a known location, for example if the application allows users to upload images.

More information is available in our blog post here.

Overview

Description
Directory Traversal vulnerability in Marimer LLC CSLA .Net before 8.0 allows a remote attacker to execute arbitrary code via a crafted script to the MobileFormatter component.
Source
cve@mitre.org
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-22

Social media

Hype score
Not currently trending