CVE-2024-50620

HIGH

CIPPlanner CIPAce <9.17 - Unrestricted Upload of File with Dangerou...

Title source: llm
STIX 2.1

Description

Unrestricted Upload of File with Dangerous Type vulnerabilities exist in the rich text editor and document manage components in CIPPlanner CIPAce before 9.17. An authorized user can upload executable files when inserting images in the rich text editor, and upload executable files when uploading files on the document management page. Those executables can be executed if they are not stored in a shared directory or if the storage directory has executed permissions.

Scores

CVSS v3 8.8
EPSS 0.0006
EPSS Percentile 16.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
cipplanner/cipace < 9.17
Published Feb 11, 2026
Tracked Since Feb 18, 2026