CVE-2024-57337
MEDIUMM2Soft CROWNIX Report & ERS <5.5.14.1070, <7.4.3.960, <8.2.0.345 - RCE
Title source: llmDescription
An arbitrary file upload vulnerability in the opcode 500 functionality of M2Soft CROWNIX Report & ERS v5.x to v5.5.14.1070, v7.x to v7.4.3.960, and v8.x to v8.2.0.345 allows attackers to execute arbitrary code via supplying a crafted file.
References (1)
Core 1
Core References
Various Sources
https://www.m2soft.co.kr/sub/board/news.asp?mode=view&idx=2411
Scores
CVSS v3
6.5
EPSS
0.0026
EPSS Percentile
16.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-77
Status
published
Published
May 28, 2025
Tracked Since
Feb 18, 2026