Podatność CVE-2024-3778


Publikacja: 2024-04-15

Opis:
The file upload functionality of Ai3 QbiBot does not properly restrict types of uploaded files, allowing remote attackers with administrator privilege to upload files with dangerous type containing malicious code.

Typ:

CWE-434

(Unrestricted Upload of File with Dangerous Type)

 Referencje:
https://www.twcert.org.tw/tw/cp-132-7732-9a54e-1.html

Copyright 2024, cxsecurity.com

 

Back to Top