CVE-2024-8330
CVE-2024-8330
Título es
CVE-2024-8330
Vie, 30/08/2024 – 03:15
Tipo
CWE-434
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2024-8330
Descripción en
6SHR system from Gether Technology does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload web shell scripts and use them to execute arbitrary system commands on the server.
30/08/2024
30/08/2024
Vector CVSS:3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Gravedad 3.1 (CVSS 3.1 Base Score)
8.80
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
HIGH
Referencias
Enviar en el boletín
Off