Upload of Dangerous File Type vulnerability in CSV to HTML allows Web Shell Upload to Web Server
CVE-2024-52406
9.9CRITICAL
What is CVE-2024-52406?
The vulnerability allows for unrestricted upload of files with potentially dangerous types within the Wibergs Web CSV to HTML product. This flaw permits the upload of web shell scripts to web servers, which can be utilized by malicious actors to execute arbitrary commands. Affected versions include all prior to 3.04. Securing input handling and implementing file type validation are essential to mitigate the risks associated with this vulnerability.
Affected Version(s)
CSV to html <= 3.04