CVE-2024-11979: Interinfo DreamMaker - Unrestricted File Upload through Path Traversal
DreamMaker from Interinfo has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11979?
CVE-2024-11979 is a high-severity vulnerability due to the risk of arbitrary code execution.
How do I fix CVE-2024-11979?
To mitigate CVE-2024-11979, ensure that file uploads are restricted to specific file types and validate directory access.
Who is affected by CVE-2024-11979?
CVE-2024-11979 affects users of Interinfo DreamMaker that allow unrestricted file uploads.
What kind of attacks can CVE-2024-11979 enable?
CVE-2024-11979 can enable unauthenticated remote attackers to upload webshells and execute arbitrary code.
Is CVE-2024-11979 exploitable without authentication?
Yes, CVE-2024-11979 can be exploited by unauthenticated attackers, making it particularly dangerous.