Directory Traversal in File Upload in Gleamtech FileVista 9.2.0.0 allows remote attackers to achieve Code Execution, Information Disclosure, and Escalation of Privileges via injecting malicious payloads in HTTP requests to manipulate file paths, bypass access controls, and upload malicious files.
History

Tue, 11 Feb 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 10 Feb 2025 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 07 Feb 2025 15:45:00 +0000

Type Values Removed Values Added
Description Directory Traversal in File Upload in Gleamtech FileVista 9.2.0.0 allows remote attackers to achieve Code Execution, Information Disclosure, and Escalation of Privileges via injecting malicious payloads in HTTP requests to manipulate file paths, bypass access controls, and upload malicious files.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-02-07T00:00:00.000Z

Updated: 2025-02-11T15:22:10.534Z

Reserved: 2025-01-09T00:00:00.000Z

Link: CVE-2024-57248

cve-icon Vulnrichment

Updated: 2025-02-10T17:27:11.755Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-02-07T16:15:38.043

Modified: 2025-02-10T18:15:32.563

Link: CVE-2024-57248

cve-icon Redhat

No data.