CVE-2024-11313

The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.
Configurations

Configuration 1 (hide)

cpe:2.3:a:trcore:dvc:*:*:*:*:*:*:*:*

History

20 Nov 2024, 15:16

Type Values Removed Values Added
CPE cpe:2.3:a:trcore:dvc:*:*:*:*:*:*:*:*
First Time Trcore
Trcore dvc
CWE CWE-23 CWE-22
References () https://www.twcert.org.tw/en/cp-139-8251-3455e-2.html - () https://www.twcert.org.tw/en/cp-139-8251-3455e-2.html - Third Party Advisory
References () https://www.twcert.org.tw/tw/cp-132-8250-1837b-1.html - () https://www.twcert.org.tw/tw/cp-132-8250-1837b-1.html - Third Party Advisory

18 Nov 2024, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-18 07:15

Updated : 2024-11-20 15:16


NVD link : CVE-2024-11313

Mitre link : CVE-2024-11313


JSON object : View

Products Affected

trcore

  • dvc
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')