PT-2026-7656 · Cipplanner · Cipace
CVE-2024-50620
·
Publicado
2026-02-11
·
Atualizado
2026-02-18
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CIPPlanner CIPAce versions prior to 9.17
Description
The software contains flaws related to unrestricted file uploads with dangerous file types in the rich text editor and document management components. A user with authorization can upload executable files through the rich text editor when inserting images and through the document management page when uploading files. If these executables are not stored in a shared directory or if the storage directory has execute permissions, they can be executed.
Recommendations
Update to version 9.17 or later.
Correção
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cipace