CVE-2024-47579

An attacker authenticated as an administrator can use an exposed webservice to upload or download a custom PDF font file on the system server. Using the upload functionality to copy an internal file into a font file and subsequently using the download functionality to retrieve that file allows the attacker to read any file on the server with no effect on integrity or availability
Configurations

No configuration.

History

10 Dec 2024, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-10 01:15

Updated : 2024-12-10 01:15


NVD link : CVE-2024-47579

Mitre link : CVE-2024-47579

CVE.ORG link : CVE-2024-47579


JSON object : View

Products Affected

No product.

CWE
CWE-538

Insertion of Sensitive Information into Externally-Accessible File or Directory