First published: Mon Feb 03 2025(Updated: )
Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible during web browsing by other users). upload.aspx can be used for this.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VeraCore | <2024.4.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-57968 is considered a medium severity vulnerability due to its potential for file upload exploitation.
To fix CVE-2024-57968, upgrade Advantive VeraCore to version 2024.4.2.1 or later.
Remote authenticated users of Advantive VeraCore versions prior to 2024.4.2.1 are affected by CVE-2024-57968.
CVE-2024-57968 is a directory traversal vulnerability that allows unintended file uploads.
The consequences of CVE-2024-57968 include unauthorized file access and potential exposure of sensitive data.