CVE-2024-57338

An arbitrary file upload vulnerability in M2Soft CROWNIX Report & ERS v5.x to v5.5.14.1070, v7.x to v7.4.3.960, and v8.x to v8.2.0.345 allows attackers to execute arbitrary code via supplying a crafted file.
Configurations

No configuration.

History

30 May 2025, 21:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
Summary
  • (es) Una vulnerabilidad de carga de archivos arbitrarios en M2Soft CROWNIX Report & ERS v5.x a v5.5.14.1070, v7.x a v7.4.3.960 y v8.x a v8.2.0.345 permite a los atacantes ejecutar código arbitrario mediante el suministro de un archivo manipulado.
CWE CWE-77

28 May 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-28 18:15

Updated : 2025-05-30 21:15


NVD link : CVE-2024-57338

Mitre link : CVE-2024-57338

CVE.ORG link : CVE-2024-57338


JSON object : View

Products Affected

No product.

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')