CVE-2024-11313

CRITICAL

TRCore - Path Traversal

Title source: llm

Description

The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.

Scores

CVSS v3 9.8
EPSS 0.0516
EPSS Percentile 89.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-22 CWE-434 CWE-23
Status published

Affected Products (1)

trcore/dvc < 6.4

Timeline

Published Nov 18, 2024
Tracked Since Feb 18, 2026