PT-2024-27781 · Mango Api+1 · Mango Api+1

CVE-2024-37847

·

Published

2024-10-25

·

Updated

2024-11-05

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MangoOS versions prior to 5.1.4 Mango API versions prior to 4.5.5
Description An arbitrary file upload issue allows attackers to execute arbitrary code via a crafted file.
Recommendations For MangoOS versions prior to 5.1.4, update to version 5.1.4 or later. For Mango API versions prior to 4.5.5, update to version 4.5.5 or later.

Exploit

Fix

Path traversal

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-37847

Affected Products

Mango Api
Mangoos