CVE-2024-24122

LOW

Wondershare Edraw - Path Traversal

Title source: rule
STIX 2.1

Description

A remote code execution vulnerability in the project management of Wanxing Technology's Yitu project which allows an attacker to use the exp.adpx file as a zip compressed file to construct a special file name, which can be used to decompress the project file into the system startup folder, restart the system, and automatically execute the constructed attack script.

Scores

CVSS v3 3.3
EPSS 0.0105
EPSS Percentile 77.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-22
Status published
Products (1)
wondershare/edraw 3.2.2
Published Oct 02, 2024
Tracked Since Feb 18, 2026