PT-2024-25947 · Unknown · Xlang Openagents

CVE-2024-34524

·

Published

2024-05-05

·

Updated

2024-07-03

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions XLANG OpenAgents versions through fe73ac4
Description The allowed file protection mechanism can be bypassed by using an incorrect file extension for the nature of the file content.
Recommendations For versions through fe73ac4, consider restricting file uploads to only those with expected extensions to minimize the risk of exploitation until a patch is available.

Fix

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-34524

Affected Products

Xlang Openagents