CVE-2024-35591: XSS
Published May 24, 2024
·Updated
An arbitrary file upload vulnerability in O2OA v8.3.8 allows attackers to execute arbitrary code via uploading a crafted PDF file.
Affected Software
2 affected components
O2OA O2OA
Zoneland O2oa
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 24, 2024
CVE Published
via NVD·02:15 PM
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Aug 29, 2024
Data Sourced
via MITRE·06:50 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-35591?
CVE-2024-35591 is rated as a high severity vulnerability due to its potential to allow arbitrary code execution.
2
How do I fix CVE-2024-35591?
To fix CVE-2024-35591, upgrade to the latest version of O2OA where the vulnerability has been patched.
3
What type of file can be exploited in CVE-2024-35591?
CVE-2024-35591 can be exploited through a crafted PDF file uploaded to the application.
4
Which versions of O2OA are affected by CVE-2024-35591?
CVE-2024-35591 affects O2OA version 8.3.8 and potentially earlier versions.
5
What actions should I take if I suspect an exploit of CVE-2024-35591?
If you suspect an exploit of CVE-2024-35591, immediately apply the patch and conduct a security audit of your system.