CVE-2024-3778

HIGH

AI3 Qbibot - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

The file upload functionality of Ai3 QbiBot does not properly restrict types of uploaded files, allowing remote attackers with administrator privilege to upload files with dangerous type containing malicious code.

References (1)

Core 1
Core References
Third Party Advisory third-party-advisory
https://www.twcert.org.tw/tw/cp-132-7732-9a54e-1.html

Scores

CVSS v3 7.2
EPSS 0.0030
EPSS Percentile 53.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
ai3/qbibot
Published Apr 15, 2024
Tracked Since Feb 18, 2026