neroteam.com
https://neroteam.com/blog/f-logic-datacube3-vulnerability-report CVE-2024-25832
HIGH
DataCube3 v1.0 - Unrestricted file upload 'RCE'
Record summary
CVE-2024-25832 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit and 1 repository PoC.
Description
F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of dangerous type by manipulating the filename extension.
Description source: CVE List
Exploitation context
Proofs of concept
2Catalogued exploits
ExploitDBDataCube3 v1.0 - Unrestricted file upload 'RCE'ExploitDB exploitby Samy Younsi - NS LabsNot analyzed1 file
Repository PoCs
GitHub0xNslabs/CVE-2024-25832-PoCRepository PoCby 0xNslabsStars: 4Not analyzed2 files
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-25832