← Back

CVE-2024-8330

nvd nist
Published: Aug 30, 2024Modified: Sep 5, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: twcert@cert.org.tw (Secondary)

Description

6SHR system from Gether Technology does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload web shell scripts and use them to execute arbitrary system commands on the server.

Affected (1)

6shr System
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions

References (2)

Source: twcert@cert.org.tw
Vendor Advisory
Source: twcert@cert.org.tw
Vendor Advisory

Timeline

No history available yet.