CVE-2024-48734: Malicious File Upload
Unrestricted file upload in /SASStudio/SASStudio/sasexec/{sessionID}/{InternalPath} in SAS Studio 9.4 allows remote attacker to upload malicious files. NOTE: this is disputed by the vendor because file upload is allowed for authorized users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-48734?
CVE-2024-48734 is considered a high severity vulnerability due to its potential for unauthorized file uploads.
How do I fix CVE-2024-48734?
To mitigate CVE-2024-48734, ensure that proper file upload validations and controls are implemented for authorized users.
Who is affected by CVE-2024-48734?
CVE-2024-48734 affects users of SAS Studio 9.4 that allow unrestricted file uploads.
Can CVE-2024-48734 lead to remote code execution?
Yes, CVE-2024-48734 may allow attackers to upload malicious files, which can lead to remote code execution.
What is the impact of CVE-2024-48734?
The impact of CVE-2024-48734 can include data breaches and unauthorized access to sensitive information.