Unrestricted Upload of File with Dangerous Type Vulnerability Affects Pathomation
CVE-2024-52490
10CRITICAL
Summary
The vulnerability in Pathomation allows an attacker to upload a web shell by exploiting an unrestricted file upload feature. This poses a severe risk as it enables unauthorized access and control over the web server. The issue has been identified in Pathomation versions from n/a to 2.5.1, reflecting a critical flaw that could compromise the integrity and confidentiality of sensitive data hosted on affected servers.
Affected Version(s)
Pathomation <= 2.5.1
References
CVSS V3.1
Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
ghsinfosec (Patchstack Alliance)