CVE-2024-7694
HIGH KEVTeamt5 Threatsonar Anti-ransomware < 3.5.0 - Unrestricted File Upload
Title source: ruleDescription
ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious files, which can be used to execute arbitrary system command on the server.
References (3)
Scores
CVSS v3
7.2
EPSS
0.0122
EPSS Percentile
78.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitation Intel
CISA KEV
2026-02-17
VulnCheck KEV
2026-02-17
ENISA EUVD
EUVD-2024-48579
Classification
CWE
CWE-434
Status
published
Affected Products (1)
teamt5/threatsonar_anti-ransomware
< 3.5.0
Timeline
Published
Aug 12, 2024
KEV Added
Feb 17, 2026
Tracked Since
Feb 18, 2026