CVE-2024-29272

Arbitrary File Upload vulnerability in VvvebJs before version 1.7.5, allows unauthenticated remote attackers to execute arbitrary code and obtain sensitive information via the sanitizeFileName parameter in save.php.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:vvveb:vvvebjs:*:*:*:*:*:*:*:*

History

28 May 2025, 19:00

Type Values Removed Values Added
CPE cpe:2.3:a:vvveb:vvvebjs:*:*:*:*:*:*:*:*
First Time Vvveb vvvebjs
Vvveb
References () https://github.com/givanz/VvvebJs/issues/343 - () https://github.com/givanz/VvvebJs/issues/343 - Exploit, Third Party Advisory, Issue Tracking
References () https://github.com/givanz/VvvebJs/commit/c6422cfd4d835c2fa6d512645e30015f24538ef0 - () https://github.com/givanz/VvvebJs/commit/c6422cfd4d835c2fa6d512645e30015f24538ef0 - Patch

22 Mar 2024, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-22 04:15

Updated : 2025-05-28 19:00


NVD link : CVE-2024-29272

Mitre link : CVE-2024-29272


JSON object : View

Products Affected

vvveb

  • vvvebjs
CWE

No CWE.