CVE-2019-14924

HIGH

gcdwebserver < 3.5.3 - Incorrect Authorization in GCDWebUploader moveItem

Title source: llm
STIX 2.1

Description

An issue was discovered in GCDWebServer before 3.5.3. The method moveItem in the GCDWebUploader class checks the FileExtension of newAbsolutePath but not oldAbsolutePath. By leveraging this vulnerability, an adversary can make an inaccessible file be available (the credential of the app, for instance).

References (3)

Core 3

Scores

CVSS v3 7.5
EPSS 0.0203
EPSS Percentile 78.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-863
Status published
Products (1)
gcdwebserver_project/gcdwebserver < 3.5.3
Published Aug 10, 2019
Tracked Since Feb 18, 2026