CVE-2024-1932: Unrestricted Upload of File with Dangerous Type in freescout-helpdesk/freescout
Published Feb 28, 2024
·Updated
Unrestricted Upload of File with Dangerous Type in freescout-helpdesk/freescout
Affected Software
1 affected component
Freescout freescout<1.8.101
Remediation
Event History
Feb 28, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-1932?
CVE-2024-1932 is classified as a high severity vulnerability due to the risk of arbitrary file uploads.
2
How do I fix CVE-2024-1932?
To fix CVE-2024-1932, users should upgrade to Freescout versions later than 1.8.101 to mitigate the vulnerability.
3
What are the potential impacts of CVE-2024-1932?
CVE-2024-1932 allows attackers to upload files of dangerous types, potentially leading to web shell access and system compromise.
4
Which versions of Freescout are affected by CVE-2024-1932?
Freescout versions up to 1.8.101 are affected by CVE-2024-1932.
5
Is user input validation a concern in CVE-2024-1932?
Yes, the vulnerability arises from inadequate user input validation during file uploads.