CVE-2024-47655

This vulnerability exists in the Shilpi Client Dashboard due to improper validation of files being uploaded other than the specified extension. An authenticated remote attacker could exploit this vulnerability by uploading malicious file, which could lead to remote code execution on targeted application.
Configurations

Configuration 1 (hide)

cpe:2.3:a:shilpisoft:client_dashboard:*:*:*:*:*:*:*:*

History

16 Oct 2024, 15:26

Type Values Removed Values Added
First Time Shilpisoft
Shilpisoft client Dashboard
CPE cpe:2.3:a:shilpisoft:client_dashboard:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
References () https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0313 - () https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0313 - Third Party Advisory

04 Oct 2024, 13:50

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-04 13:15

Updated : 2024-10-16 15:26


NVD link : CVE-2024-47655

Mitre link : CVE-2024-47655


JSON object : View

Products Affected

shilpisoft

  • client_dashboard
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type