PoC Index

CVE-2024-29272

MEDIUM 6.9EPSS 9.4%

Arbitrary File Upload vulnerability in VvvebJs before version 1.7.5, allows unauthenticated remote attackers to execute arbitrary code and obtain sensitive information via the sanitizeFileName parameter in save.php.

CVSS v4.0
6.9 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS v3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS v3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS
9.37% chance of exploitation in the next 30 days, 95th percentile
Nuclei
medium · CWE-434
Published
2024-03-22
Updated
2024-08-02

Proof-of-concept exploits (2)

Nuclei templates (1)

References

Related