CVE-2024-11315
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Nov 18, 2024
Updated: Nov 20, 2024
CWE ID 23
CWE ID 434
CWE ID 22
Summary
CVE-2024-11315 introduces a significant vulnerability in the TRCore DVC system. An unauthenticated attacker can exploit this Path Traversal issue, which fails to restrict the types of uploaded files. By uploading arbitrary files, they can gain the ability to execute arbitrary code, likely through the introduction of webshells. This vulnerability poses a severe threat to the security of the affected system.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- DVC