CVE-2024-55926

A vulnerability found in Xerox Workplace Suite allows arbitrary file read, upload, and deletion on the server through crafted header manipulation. By exploiting improper validation of headers, attackers can gain unauthorized access to data
Configurations

No configuration.

History

29 Jan 2025, 12:15

Type Values Removed Values Added
References
  • {'url': 'https://securitydocs.business.xerox.com/wp-content/uploads/2025/01/Xerox-Security-Bulletin-XRX25-002-for-Xerox%C2%AE-Workplace-Suite%C2%AE.pdf', 'source': '10b61619-3869-496c-8a1e-f291b0e71e3f'}
  • () https://securitydocs.business.xerox.com/wp-content/uploads/2025/01/Xerox-Security-Bulletin-XRX25-002-for-Xerox%C2%AE-WorkplaceSuite%C2%AE.pdf -

27 Jan 2025, 11:15

Type Values Removed Values Added
Summary
  • (es) Carga, eliminación y lectura arbitraria de archivos mediante manipulación del encabezado
Summary (en) Arbitrary file upload, deletion and read through header manipulation (en) A vulnerability found in Xerox Workplace Suite allows arbitrary file read, upload, and deletion on the server through crafted header manipulation. By exploiting improper validation of headers, attackers can gain unauthorized access to data

23 Jan 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-23 18:15

Updated : 2025-01-29 12:15


NVD link : CVE-2024-55926

Mitre link : CVE-2024-55926

CVE.ORG link : CVE-2024-55926


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-434

Unrestricted Upload of File with Dangerous Type