CVE-2024-55372: Critical severity wallos vulnerability
Wallos <=2.38.2 has a file upload vulnerability in the restore database function, which allows unauthenticated users to restore database by uploading a ZIP file. The contents of the ZIP file are extracted on the server. This functionality enables an unauthenticated attacker to upload malicious files to the server. Once a web shell is installed, the attacker gains the ability to execute arbitrary commands.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-55372?
The severity of CVE-2024-55372 is high due to its potential to allow unauthorized users to restore databases by uploading malicious files.
How do I fix CVE-2024-55372?
To fix CVE-2024-55372, upgrade to Wallos version 2.38.3 or later, which addresses the file upload vulnerability.
Who is affected by CVE-2024-55372?
CVE-2024-55372 affects all versions of Wallos up to and including 2.38.2.
What attack vectors are associated with CVE-2024-55372?
CVE-2024-55372 allows unauthenticated attackers to restore databases via malicious ZIP file uploads.
What are the consequences of exploiting CVE-2024-55372?
Exploiting CVE-2024-55372 can lead to arbitrary file execution on the server, potentially compromising the entire application.