CVE-2024-24025: Malicious File Upload
An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.FileController: upload(). An attacker can pass in specially crafted filename parameter to perform arbitrary File download.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24025?
CVE-2024-24025 is assigned a high severity rating due to its potential for arbitrary file upload that can lead to various attacks.
How do I fix CVE-2024-24025?
To fix CVE-2024-24025, update Novell-Plus to version 4.3.0-RC2 or later which addresses the arbitrary file upload vulnerability.
Which versions are affected by CVE-2024-24025?
CVE-2024-24025 affects Novel-Plus versions 4.3.0-RC1 and earlier versions up to 4.2.0.
What type of attack can CVE-2024-24025 facilitate?
CVE-2024-24025 can facilitate attacks such as unauthorized file downloads and potential remote code execution.
How does CVE-2024-24025 exploit file upload functionality?
CVE-2024-24025 exploits the file upload functionality by allowing attackers to manipulate the filename parameter to upload malicious files.