CVE-2024-55372

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Apr 16, 2025
Updated: Apr 17, 2025
CWE ID 73

Summary

CVE-2024-55372 is a file upload vulnerability affecting Wallos versions below 2.38.2. The issue lies in the restore database function, which can be exploited by unauthenticated users. By uploading a malicious ZIP file, an attacker can extract its contents on the server, potentially installing a web shell. This grants the attacker the ability to execute arbitrary commands, compromising the server's security.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share