File Upload Vulnerability in Znuny and Znuny LTS Affected by Path Traversal
CVE-2024-32491
9.8CRITICAL
What is CVE-2024-32491?
A vulnerability in Znuny and Znuny LTS versions 6.0.31 up to 6.5.7 and 7.0.1 to 7.0.16 allows an authenticated user to exploit path traversal techniques. By crafting a specific AJAX request, an attacker can upload files to arbitrary writable locations on the server. If these locations are accessible through the web server, it leads to the potential execution of arbitrary code, introducing significant security risks to affected systems.
