CVE-2024-8338
Hfo4
CVE-2024-8338: Critical unrestricted file upload vulnerability in HFO4 shudong-share 2.4.7. This vulnerability allows remote attackers to upload arbitrary files via the /includes/fileReceive.php
endpoint by manipulating the file
argument, leading to potential system compromise. The CVSS score is 8.8, but with an SVRS of 77, the risk is high and approaching critical levels. Although the product is no longer supported, the public availability of the exploit makes it imperative to assess and mitigate this security risk if legacy systems are still in use. Exploitation can result in arbitrary code execution or data breach. Users should immediately isolate or decommission affected systems if patching is not possible. The CWE-434 is associated with this CVE.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.