CVE-2024-48448
CVE-2024-48448 is an arbitrary file upload vulnerability in Huly Platform v0.6.295, potentially allowing attackers to execute arbitrary code. By uploading a specially crafted HTML file through the tracker comments page, malicious actors can compromise the system. The SVRS score of 30 suggests a moderate risk, indicating that while the vulnerability is present, its exploitation is not considered highly critical at this time. This vulnerability is due to improper handling of file uploads, leading to a Cross-Site Scripting (XSS) risk. Although the CVSS score is 0, the arbitrary file upload could bypass security measures and allow remote code execution after successful exploitation. While not immediately critical, CVE-2024-48448 should be addressed to prevent potential attacks and maintain system security.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.