CVE-2024-57968

Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible during web browsing by other users). upload.aspx can be used for this.
Configurations

Configuration 1 (hide)

cpe:2.3:a:advantive:veracore:*:*:*:*:*:*:*:*

History

13 Mar 2025, 14:31

Type Values Removed Values Added
References () https://advantive.my.site.com/support/s/article/VeraCore-Release-Notes-2024-4-2-1 - () https://advantive.my.site.com/support/s/article/VeraCore-Release-Notes-2024-4-2-1 - Product, Release Notes
References () https://www.solissecurity.com/en-us/insights/xe-group-from-credit-card-skimming-to-exploiting-zero-days/ - () https://www.solissecurity.com/en-us/insights/xe-group-from-credit-card-skimming-to-exploiting-zero-days/ - Exploit, Technical Description, Third Party Advisory
References () https://intezer.com/blog/research/xe-group-exploiting-zero-days/ - () https://intezer.com/blog/research/xe-group-exploiting-zero-days/ - Exploit, Technical Description, Third Party Advisory
CPE cpe:2.3:a:advantive:veracore:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
First Time Advantive veracore
Advantive
CWE CWE-434

06 Feb 2025, 18:15

Type Values Removed Values Added
References
  • () https://www.solissecurity.com/en-us/insights/xe-group-from-credit-card-skimming-to-exploiting-zero-days/ -

03 Feb 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-03 20:15

Updated : 2025-03-13 14:31


NVD link : CVE-2024-57968

Mitre link : CVE-2024-57968


JSON object : View

Products Affected

advantive

  • veracore
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type