CVE-2024-28269

HIGH

ReCrystallize Server <5.10.0.0 - RCE

Title source: llm
STIX 2.1

Description

ReCrystallize Server 5.10.0.0 allows administrators to upload files to the server. The file upload is not restricted, leading to the ability to upload of malicious files. This could result in a Remote Code Execution.

Scores

CVSS v3 7.2
EPSS 0.0234
EPSS Percentile 84.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Published Apr 30, 2024
Tracked Since Feb 18, 2026