Arbitrary File Upload Vulnerability Allows Execution of Arbitrary Code
CVE-2024-46482
8.2HIGH
What is CVE-2024-46482?
An arbitrary file upload vulnerability exists in the Ticket Generation function of Faveo-Helpdesk v2.0.3 from Ladybird Web Solutions. This flaw permits an attacker to upload specially crafted files, such as .html or .svg, which may lead to the execution of arbitrary code on the server. Consequently, this can compromise the integrity and confidentiality of the application, allowing unauthorized access to sensitive information and potential disruption of services.
