CVE-2024-56829

Published Jan 2, 2025

Last updated 2 months ago

Overview

Description
Huang Yaoshi Pharmaceutical Management Software through 16.0 allows arbitrary file upload via a .asp filename in the fileName element of the UploadFile element in a SOAP request to /XSDService.asmx.
Source
cve@mitre.org
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
10
Impact score
6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

cve@mitre.org
CWE-434

Social media

Hype score
Not currently trending
  1. CVE-2024-56829 (CVSS:10.0, CRITICAL) is Awaiting Analysis. Huang Yaoshi Pharmaceutical Management Software through 16.0 allows arbitrary file upload via a .asp filename in the fil..https://t.co/0UtPLlNJWr #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    7 Jan 2025

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2024-56829 (CVSS:10.0, CRITICAL) is Awaiting Analysis. Huang Yaoshi Pharmaceutical Management Software through 16.0 allows arbitrary file upload via a .asp filename in the fil..https://t.co/0UtPLlNJWr #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    6 Jan 2025

    29 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 #Breakingnews: "CVE-2024-56829" A new CVE detected - with severity "10.0 | CRITICAL". More: https://t.co/qqTmGFQvro 📢 Follow us for more updates! #CVE #ThreatAlert #InfoSec #CriticalVulnerability

    @bluepinksec

    3 Jan 2025

    10 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2024-56829 Arbitrary File Upload in Huang Yaoshi Software Through 16.0 Huang Yaoshi Pharmaceutical Management Software up to version 16.0 allows file uploads with arbitrary .asp filenames. This happens in the... https://t.co/LBCambW1j6

    @VulmonFeeds

    2 Jan 2025

    57 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2024-56829 Huang Yaoshi Pharmaceutical Management Software through 16.0 allows arbitrary file upload via a .asp filename in the fileName element of the UploadFile element in a S… https://t.co/GfjrIOO9mg

    @CVEnew

    2 Jan 2025

    602 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. [CVE-2024-56829: CRITICAL] #CyberSecurity alert! Huang Yaoshi Pharmaceutical Management Software v16.0 vulnerability allows for arbitrary file uploads via a SOAP request. Update recommended ASAP!#cybersecurity,#vulnerability https://t.co/ecTno6RMCI https://t.co/cPZlAlV47d

    @CveFindCom

    2 Jan 2025

    64 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes