CVE-2024-52302

HIGH

common-user-management - RCE

Title source: llm

Description

common-user-management is a robust Spring Boot application featuring user management services designed to control user access dynamically. There is a critical security vulnerability in the application endpoint /api/v1/customer/profile-picture. This endpoint allows file uploads without proper validation or restrictions, enabling attackers to upload malicious files that can lead to Remote Code Execution (RCE).

Exploits (3)

exploitdb WORKING POC
by d3sca · pythonwebappsjava
https://www.exploit-db.com/exploits/52206
nomisec WORKING POC 1 stars
by d3sca · poc
https://github.com/d3sca/CVE-2024-52302
nomisec WORKING POC
by pream-totaram · poc
https://github.com/pream-totaram/CVE-2024-52302-reproduction

Scores

CVSS v4 8.7
EPSS 0.0438
EPSS Percentile 89.0%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Details

CWE
CWE-434
Status published
Products (1)
OsamaTaher/Java-springboot-codebase < 204402bb8b68030c14911379ddc82cfff00b8538
Published Nov 14, 2024
Tracked Since Feb 18, 2026