CVE-2024-29399
HIGHGNU Savane < 3.13 - Remote Code Execution via upload.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-29399. PoCs published by ally-petitt.
AI-analyzed exploit summary CVE-2024-29399 exploits an unrestricted file upload vulnerability in Savane v3.13 and prior, allowing XSS or RCE depending on server configuration. The PoC demonstrates file uploads of malicious HTML or PHP files to achieve code execution.
Description
An issue was discovered in GNU Savane v.3.13 and before, allows a remote attacker to execute arbitrary code and escalate privileges via a crafted file to the upload.php component.
Exploits (1)
CVE-2024-29399 exploits an unrestricted file upload vulnerability in Savane v3.13 and prior, allowing XSS or RCE depending on server configuration. The PoC demonstrates file uploads of malicious HTML or PHP files to achieve code execution.
References (1)
Scores
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L