Arbitrary File Upload Vulnerability Allows Execution of Arbitrary Code
CVE-2024-46482

8.2HIGH

Key Information:

Vendor
CVE Published:
22 October 2024

What is CVE-2024-46482?

An arbitrary file upload vulnerability exists in the Ticket Generation function of Faveo-Helpdesk v2.0.3 from Ladybird Web Solutions. This flaw permits an attacker to upload specially crafted files, such as .html or .svg, which may lead to the execution of arbitrary code on the server. Consequently, this can compromise the integrity and confidentiality of the application, allowing unauthorized access to sensitive information and potential disruption of services.

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.