CVE-2024-11314
CRITICALTRCore - Path Traversal
Title source: llmDescription
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.
Scores
CVSS v3
9.8
EPSS
0.0516
EPSS Percentile
89.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-22
CWE-434
CWE-23
Status
published
Affected Products (1)
trcore/dvc
< 6.4
Timeline
Published
Nov 18, 2024
Tracked Since
Feb 18, 2026