CVE-2024-0643

CRITICAL

C21 Live Encoder & Live Mosaic <5.3 - RCE

Title source: llm
STIX 2.1

Description

Unrestricted upload of dangerous file types in the C21 Live Encoder and Live Mosaic product, version 5.3. This vulnerability allows a remote attacker to upload different file extensions without any restrictions, resulting in a full system compromise.

Scores

CVSS v3 10.0
EPSS 0.0044
EPSS Percentile 63.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
cires21/live_encoder 5.3
Published Jan 17, 2024
Tracked Since Feb 18, 2026