CVE-2024-11017
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Nov 11, 2024
Updated: Nov 12, 2024
CWE ID 434
Summary
CVE-2024-11017 is a vulnerability affecting Grand Vice info's Webopac software. The issue arises from the software's failure to adequately validate uploaded file types. Malicious actors with regular privileges can exploit this vulnerability by uploading webshells, giving them the ability to execute arbitrary code on the server. This weakness could result in significant security risks for affected systems.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.