CVE-2024-11314

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Nov 18, 2024
Updated: Nov 20, 2024
CWE ID 434
CWE ID 23
CWE ID 22

Summary

CVE-2024-11314 is a newly discovered vulnerability affecting the DVC tool from TRCore. This issue involves a path traversal weakness, permitting unauthenticated attackers to upload any file type to any directory. Successful exploitation of this vulnerability can result in arbitrary code execution through the upload of webshells. This poses a significant risk, as attackers can gain control over the affected system and potentially steal sensitive information or cause further damage. It is essential that users of TRCore's DVC tool apply the necessary patches or updates as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share