CVE-2024-11017

HIGH

Vice Webopac < 6.5.1 - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

Webopac from Grand Vice info does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload and execute webshells, which could lead to arbitrary code execution on the server.

References (2)

Core 2
Core References
Third Party Advisory third-party-advisory
https://www.twcert.org.tw/tw/cp-132-8211-a2da2-1.html
Third Party Advisory third-party-advisory
https://www.twcert.org.tw/en/cp-139-8212-a7d3a-2.html

Scores

CVSS v3 8.8
EPSS 0.0206
EPSS Percentile 84.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
vice/webopac 6 - 6.5.1
Published Nov 11, 2024
Tracked Since Feb 18, 2026