First published: Wed Feb 28 2024(Updated: )
F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of dangerous type by manipulating the filename extension.
Credit: cve@mitre.org Samy Younsi - NS Labs
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
=1.0 | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-25832 is considered a critical vulnerability due to the potential for unrestricted file uploads.
To fix CVE-2024-25832, implement strict validation on file uploads to limit allowed file types and thoroughly sanitize filenames.
CVE-2024-25832 affects users of F-logic DataCube3 version 1.0.
An attacker could exploit CVE-2024-25832 to upload malicious files that can compromise the security of the server.
CVE-2024-25832 requires authentication, meaning that an attacker must have valid user credentials to exploit the vulnerability.