CVE-2024-3804

MEDIUM EXPLOITED

Vesystem Cloud Desktop <20240408 - Unrestricted Upload

Title source: llm
STIX 2.1

Description

A vulnerability, which was classified as critical, has been found in Vesystem Cloud Desktop up to 20240408. This issue affects some unknown processing of the file /Public/webuploader/0.1.5/server/fileupload2.php. The manipulation of the argument file leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-260777 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

References (4)

Core 4
Core References
Permissions Required, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.260777
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.260777
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.312318

Scores

CVSS v3 6.3
EPSS 0.0016
EPSS Percentile 37.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

VulnCheck KEV 2025-06-08
CWE
CWE-434
Status published
Products (1)
Vesystem/Cloud Desktop 20240408
Published Apr 15, 2024
Tracked Since Feb 18, 2026