PT-2026-7656 · Cipplanner · Cipace

CVE-2024-50620

·

Publicado

2026-02-11

·

Atualizado

2026-02-18

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CIPPlanner CIPAce versions prior to 9.17
Description The software contains flaws related to unrestricted file uploads with dangerous file types in the rich text editor and document management components. A user with authorization can upload executable files through the rich text editor when inserting images and through the document management page when uploading files. If these executables are not stored in a shared directory or if the storage directory has execute permissions, they can be executed.
Recommendations Update to version 9.17 or later.

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2024-50620

Produtos afetados

Cipace