CVE Radar Logo
CVERadar
CVE Radar Logo
CVERadar

CVE-2024-8338

Critical Severity
Hfo4
SVRS
77/100

CVSSv3
8.8/10

EPSS
0.0015/1

CVE-2024-8338: Critical unrestricted file upload vulnerability in HFO4 shudong-share 2.4.7. This vulnerability allows remote attackers to upload arbitrary files via the /includes/fileReceive.php endpoint by manipulating the file argument, leading to potential system compromise. The CVSS score is 8.8, but with an SVRS of 77, the risk is high and approaching critical levels. Although the product is no longer supported, the public availability of the exploit makes it imperative to assess and mitigate this security risk if legacy systems are still in use. Exploitation can result in arbitrary code execution or data breach. Users should immediately isolate or decommission affected systems if patching is not possible. The CWE-434 is associated with this CVE.

No tags available
CVSS:3.1
AV:N
AC:L
PR:L
UI:N
S:U
C:H
I:H
A:H
2024-08-30

2024-09-25

Indicators of Compromise

No IOCs found for this CVE

Exploits

No exploits found for this CVE

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

News

No news found for this CVE

Social Media

CVE-2024-8338 A vulnerability was found in HFO4 shudong-share 2.4.7. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /include… https://t.co/CZaW7PNoRq
0
0
0

Affected Software

Configuration 1
TypeVendorProduct
AppHfo4shudong-share

References

ReferenceLink
[email protected]https://github.com/enjoyworld/webray.com.cn/blob/main/cves/shudong-share%20Any%20File%20Upload.md
[email protected]https://vuldb.com/?ctiid.276217
[email protected]https://vuldb.com/?id.276217
[email protected]https://vuldb.com/?submit.399538
GITHUBhttps://github.com/enjoyworld/webray.com.cn/blob/main/cves/shudong-share%20Any%20File%20Upload.md

CWE Details

CWE IDCWE NameDescription
CWE-434Unrestricted Upload of File with Dangerous TypeThe software allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

Get Free Vulnerability Intelligence AccessAccess real-time CVE monitoring, exploit analysis, and threat intelligence