CVE-2024-11017

HIGH

Vice Webopac 6-6.5.1 - Authenticated Unrestricted Upload of File with Dangerous Type

Title source: llm
STIX 2.1

Description

Webopac from Grand Vice info does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload and execute webshells, which could lead to arbitrary code execution on the server.

References (2)

Core 2
Core References
Third Party Advisory third-party-advisory
https://www.twcert.org.tw/tw/cp-132-8211-a2da2-1.html
Third Party Advisory third-party-advisory
https://www.twcert.org.tw/en/cp-139-8212-a7d3a-2.html

Scores

CVSS v3 8.8
EPSS 0.0074
EPSS Percentile 49.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
vice/webopac 6 - 6.5.1
Published Nov 11, 2024
Tracked Since Feb 18, 2026