PT-2024-34306 · Unknown · Rudra Innovative Software Training – Courses

·

CVE-2024-50529

·

Published

2024-11-04

·

Updated

2024-11-06

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Rudra Innovative Software Training – Courses versions prior to 2.0.1
Description: The issue allows unauthorized upload of malicious files, specifically a web shell, to a web server. This poses a significant risk to the security of the web server.
Recommendations: For versions prior to 2.0.1, update to version 2.0.1 to fix the issue. As a temporary workaround, consider restricting file uploads to prevent potential exploitation until the update can be applied.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-50529

Affected Products

Rudra Innovative Software Training – Courses