First published: Tue Sep 24 2024(Updated: )
Vulnerability in the Scriptcase application version 9.4.019, which involves the arbitrary upload of a file via /scriptcase/devel/lib/third/jquery_plugin/jQuery-File-Upload/server/php/ via a POST request. An attacker could upload malicious files to the server due to the application not properly verifying user input.
Credit: cve-coordination@incibe.es
Affected Software | Affected Version | How to fix |
---|---|---|
Scriptcase | =9.4.019 |
The vulnerability has been fixed in the latest version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-8940 is considered a critical vulnerability due to its potential for arbitrary file uploads.
To fix CVE-2024-8940, upgrade to Scriptcase version 9.4.020 or later.
CVE-2024-8940 allows attackers to upload malicious files to the server, which can lead to further exploitation or data breaches.
If you are using Scriptcase version 9.4.019, your version is affected by CVE-2024-8940.
CVE-2024-8940 specifically involves the jQuery File Upload component located at /scriptcase/devel/lib/third/jquery_plugin/jQuery-File-Upload/server/php.