CVE-2024-47655

HIGH

Shilpi Client Dashboard - RCE

Title source: llm
STIX 2.1

Description

This vulnerability exists in the Shilpi Client Dashboard due to improper validation of files being uploaded other than the specified extension. An authenticated remote attacker could exploit this vulnerability by uploading malicious file, which could lead to remote code execution on targeted application.

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.0274
EPSS Percentile 86.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
shilpisoft/client_dashboard < 9.7.0
Published Oct 04, 2024
Tracked Since Feb 18, 2026