CVE-2024-47655

This vulnerability exists in the Shilpi Client Dashboard due to improper validation of files being uploaded other than the specified extension. An authenticated remote attacker could exploit this vulnerability by uploading malicious file, which could lead to remote code execution on targeted application.
Configurations

Configuration 1 (hide)

cpe:2.3:a:shilpisoft:client_dashboard:*:*:*:*:*:*:*:*

History

16 Oct 2024, 15:26

Type Values Removed Values Added
References () https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0313 - () https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0313 - Third Party Advisory
First Time Shilpisoft client Dashboard
Shilpisoft
Summary
  • (es) Esta vulnerabilidad existe en Shilpi Client Dashboard debido a la validación incorrecta de archivos que se cargan con una extensión distinta a la especificada. Un atacante remoto autenticado podría aprovechar esta vulnerabilidad cargando un archivo malicioso, lo que podría provocar la ejecución remota de código en la aplicación de destino.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CPE cpe:2.3:a:shilpisoft:client_dashboard:*:*:*:*:*:*:*:*

04 Oct 2024, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-04 13:15

Updated : 2024-10-16 15:26


NVD link : CVE-2024-47655

Mitre link : CVE-2024-47655

CVE.ORG link : CVE-2024-47655


JSON object : View

Products Affected

shilpisoft

  • client_dashboard
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type