CVE-2024-0418

MEDIUM

upRedSun File Sharing Wizard <= 1.5.0 - Denial of Service via GET Request Handler

Title source: llm
STIX 2.1

Description

A vulnerability has been found in iSharer and upRedSun File Sharing Wizard up to 1.5.0 and classified as problematic. This vulnerability affects unknown code of the component GET Request Handler. The manipulation leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-250438 is the identifier assigned to this vulnerability.

References (4)

Core 4
Core References
Permissions Required, Third Party Advisory, VDB Entry vdb-entry
https://vuldb.com/?id.250438
Permissions Required, Third Party Advisory, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.250438
Exploit, Third Party Advisory media-coverage
https://www.youtube.com/watch?v=WK7xK9KHiMU
Exploit, Third Party Advisory exploit issue-tracking
https://cxsecurity.com/issue/WLB-2024010023

Scores

CVSS v3 5.3
EPSS 0.0132
EPSS Percentile 67.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-404
Status published
Products (1)
upredsun/file_sharing_wizard < 1.5.0
Published Jan 11, 2024
Tracked Since Feb 18, 2026