Vulnerability CVE-2024-25832


Published: 2024-02-29

Description:
F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of dangerous type by manipulating the filename extension.

See advisories in our WLB2 database:
Topic
Author
Date
High
DataCube3 1.0 Shell Upload
Samy Younsi
11.03.2024

Type:

CWE-264

(Permissions, Privileges, and Access Controls)

 References:
https://neroteam.com/blog/f-logic-datacube3-vulnerability-report

Copyright 2024, cxsecurity.com

 

Back to Top