CVE-2024-26503

Unrestricted File Upload vulnerability in Greek Universities Network Open eClass v.3.15 and earlier allows attackers to run arbitrary code via upload of crafted file to certbadge.php endpoint.
Configurations

No configuration.

History

21 Nov 2024, 09:02

Type Values Removed Values Added
References () https://www.less-secure.com/2024/03/open-eclass-cve-2024-26503-unrestricted.html - () https://www.less-secure.com/2024/03/open-eclass-cve-2024-26503-unrestricted.html -

28 Aug 2024, 15:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
CWE CWE-434
Summary
  • (es) Vulnerabilidad de carga de archivos sin restricciones en la red de universidades griegas Open eClass v.3.15 y anteriores permite a los atacantes ejecutar código arbitrario mediante la carga de un archivo manipulado al endpoint certbadge.php.

14 Mar 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-14 22:15

Updated : 2024-11-21 09:02


NVD link : CVE-2024-26503

Mitre link : CVE-2024-26503

CVE.ORG link : CVE-2024-26503


JSON object : View

Products Affected

No product.

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type