Arbitrary File Upload Vulnerability Allows Execution of Arbitrary Code
CVE-2024-40318
7.2HIGH
Summary
An arbitrary file upload vulnerability exists in Webkul Qloapps v1.6.0.0, allowing attackers to upload a specially crafted file which can lead to the execution of arbitrary code. This vulnerability poses a serious threat as it may enable malicious actors to gain unauthorized access and control over the affected system. Organizations using this version of Qloapps should take immediate action to mitigate the risks associated with this security flaw.
References
EPSS Score
6% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published