CVE-2024-9985: Ragic Enterprise Cloud Database - Arbitrary File Upload
Published Oct 15, 2024
·Updated
Enterprise Cloud Database from Ragic does not properly validate the file type for uploads. Attackers with regular privileges can upload a webshell and use it to execute arbitrary code on the remote server.
Affected Software
1 affected component
Ragic Enterprise Cloud Database<2024-08-08
Remediation
Information
Update to version 2024/08/08 09:45:25 or later.
Event History
Oct 15, 2024
CVE Published
via MITRE·08:20 AM
Data Sourced
via MITRE·08:20 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-9985?
CVE-2024-9985 is classified as a high-severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2024-9985?
To fix CVE-2024-9985, ensure that input validation mechanisms for file uploads are properly implemented to restrict file types.
3
What are the potential impacts of CVE-2024-9985?
The potential impacts of CVE-2024-9985 include unauthorized access and control over the server through uploaded webshells.
4
Which software is affected by CVE-2024-9985?
CVE-2024-9985 affects Ragic's Enterprise Cloud Database versions prior to 2024-08-08.
5
Who can exploit CVE-2024-9985?
Attackers with regular user privileges can exploit CVE-2024-9985 to upload malicious files.