CVE-2024-55371: Critical severity wallos vulnerability
Wallos <= 2.38.2 has a file upload vulnerability in the restore backup function, which allows authenticated users to restore backups by uploading a ZIP file. The contents of the ZIP file are extracted on the server. This functionality enables an authenticated attacker (being an administrator is not required) to upload malicious files to the server. Once a web shell is installed, the attacker gains the ability to execute arbitrary commands.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-55371?
CVE-2024-55371 is considered a high severity vulnerability due to its file upload capabilities allowing unauthorized access to server files.
How do I fix CVE-2024-55371?
To fix CVE-2024-55371, upgrade Wallos to a version later than 2.38.2 where the vulnerability is patched.
What specific vulnerability does CVE-2024-55371 address?
CVE-2024-55371 addresses a file upload vulnerability in the restore backup function of Wallos that allows authenticated users to upload arbitrary ZIP files.
Who is affected by CVE-2024-55371?
Authenticated users with access to the restore backup functionality in Wallos versions up to and including 2.38.2 are affected by CVE-2024-55371.
Can attackers exploit CVE-2024-55371 without administrator privileges?
Yes, attackers can exploit CVE-2024-55371 with only authenticated user privileges, making it particularly concerning.