Unrestricted File Upload Vulnerability Leads to Code Injection
CVE-2024-35767
9.1CRITICAL
What is CVE-2024-35767?
The Squeeze plugin by Bogdan Bendziukov is susceptible to an unrestricted file upload vulnerability, which permits attackers to upload files with dangerous types. This flaw introduces a significant risk of code injection, potentially allowing unauthorized access or execution of malicious code on affected systems. The affected versions include Squeeze: n/a through 1.4, highlighting the importance of applying security patches and updates to mitigate these risks.
Affected Version(s)
Squeeze <= 1.4