Record summary

CVE-2024-25832 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit and 1 repository PoC.

Description

F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of dangerous type by manipulating the filename extension.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 1, 2024 · Source: CVE List

Proofs of concept

2

Catalogued exploits

ExploitDBDataCube3 v1.0 - Unrestricted file upload 'RCE'ExploitDB exploitby Samy Younsi - NS LabsNot analyzed1 file

linked to 2 vulnerabilities

ExploitDB

PoC details

Repository PoCs

GitHub0xNslabs/CVE-2024-25832-PoCRepository PoCby 0xNslabsStars: 4Not analyzed2 files

9.0 KiB

GitHub

PoC details

References

2