CVE-2024-57968

Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible during web browsing by other users). upload.aspx can be used for this.
Configurations

Configuration 1 (hide)

cpe:2.3:a:advantive:veracore:*:*:*:*:*:*:*:*

History

13 Mar 2025, 14:31

Type Values Removed Values Added
CPE cpe:2.3:a:advantive:veracore:*:*:*:*:*:*:*:*
References () https://advantive.my.site.com/support/s/article/VeraCore-Release-Notes-2024-4-2-1 - () https://advantive.my.site.com/support/s/article/VeraCore-Release-Notes-2024-4-2-1 - Product, Release Notes
References () https://intezer.com/blog/research/xe-group-exploiting-zero-days/ - () https://intezer.com/blog/research/xe-group-exploiting-zero-days/ - Exploit, Technical Description, Third Party Advisory
References () https://www.solissecurity.com/en-us/insights/xe-group-from-credit-card-skimming-to-exploiting-zero-days/ - () https://www.solissecurity.com/en-us/insights/xe-group-from-credit-card-skimming-to-exploiting-zero-days/ - Exploit, Technical Description, Third Party Advisory
First Time Advantive
Advantive veracore

06 Feb 2025, 18:15

Type Values Removed Values Added
Summary
  • (es) Las versiones anteriores a 2024.4.2.1 de Advantive VeraCore permiten que usuarios autenticados de forma remota carguen archivos en carpetas no deseadas (por ejemplo, aquellas a las que otros usuarios pueden acceder durante la navegación web). Se puede usar upload.aspx para esto.
References
  • () https://www.solissecurity.com/en-us/insights/xe-group-from-credit-card-skimming-to-exploiting-zero-days/ -

03 Feb 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-03 20:15

Updated : 2025-03-13 14:31


NVD link : CVE-2024-57968

Mitre link : CVE-2024-57968

CVE.ORG link : CVE-2024-57968


JSON object : View

Products Affected

advantive

  • veracore
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type