Local File Inclusion in Zenitel AlphaWeb XE by Zenitel
CVE-2024-57785
4.9MEDIUM
What is CVE-2024-57785?
Zenitel AlphaWeb XE v11.2.3.10 contains a local file inclusion (LFI) vulnerability found in the amc_uploads.php component. This issue allows an attacker to access unauthorized files on the server, potentially leading to further exploitation of the application and its environment. Prompt action is advised for users of the affected versions to mitigate potential risks.
References
EPSS Score
16% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
