CVE-2024-55372
CRITICALWallos <= 2.38.2 - Unauthenticated Arbitrary File Write via Database Restore Function
Title source: llmDescription
Wallos <=2.38.2 has a file upload vulnerability in the restore database function, which allows unauthenticated users to restore database by uploading a ZIP file. The contents of the ZIP file are extracted on the server. This functionality enables an unauthenticated attacker to upload malicious files to the server. Once a web shell is installed, the attacker gains the ability to execute arbitrary commands.
References (1)
Core 1
Core References
Exploit, Third Party Advisory
https://www.datafarm.co.th/blog/CVE-2024-55371-and-CVE-2024-55372-Malicious-File-Upload-to-RCE-in-Wallos-Application
Scores
CVSS v3
9.8
EPSS
0.0051
EPSS Percentile
39.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-73
Status
published
Products (1)
wallosapp/wallos
< 2.38.2
Published
Apr 16, 2025
Tracked Since
Feb 18, 2026