CVE-2024-24122

A remote code execution vulnerability in the project management of Wanxing Technology's Yitu project which allows an attacker to use the exp.adpx file as a zip compressed file to construct a special file name, which can be used to decompress the project file into the system startup folder, restart the system, and automatically execute the constructed attack script.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wondershare:edraw:3.2.2:*:*:*:*:*:*:*

History

21 Nov 2024, 08:58

Type Values Removed Values Added
CWE CWE-22

13 Nov 2024, 21:40

Type Values Removed Values Added
References () https://gist.github.com/zty-1995/effed155177edd7b22fdf2c082e32984 - () https://gist.github.com/zty-1995/effed155177edd7b22fdf2c082e32984 - Third Party Advisory
References () https://github.com/zty007666/Shenzhen-Yitu-Software-Yitu-Project-Management-Software/tree/0215da8db607824bc9523ce7532f8fc53ba1b40a/Remote%20Code%20Execution%20Vulnerability_02 - () https://github.com/zty007666/Shenzhen-Yitu-Software-Yitu-Project-Management-Software/tree/0215da8db607824bc9523ce7532f8fc53ba1b40a/Remote%20Code%20Execution%20Vulnerability_02 - Exploit, Third Party Advisory
CPE cpe:2.3:a:wondershare:edraw:3.2.2:*:*:*:*:*:*:*
First Time Wondershare
Wondershare edraw
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 3.3
CWE NVD-CWE-noinfo

04 Oct 2024, 13:50

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de ejecución remota de código en la gestión de proyectos del proyecto Yitu de Wanxing Technology que permite a un atacante utilizar el archivo exp.adpx como un archivo comprimido zip para construir un nombre de archivo especial, que puede usarse para descomprimir el archivo del proyecto en la carpeta de inicio del sistema, reiniciar el sistema y ejecutar automáticamente el script de ataque construido.

02 Oct 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-02 18:15

Updated : 2024-11-21 08:58


NVD link : CVE-2024-24122

Mitre link : CVE-2024-24122

CVE.ORG link : CVE-2024-24122


JSON object : View

Products Affected

wondershare

  • edraw
CWE
NVD-CWE-noinfo CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')