High severity8.8NVD Advisory· Published Mar 1, 2022· Updated Jul 9, 2026
CVE-2022-24254
CVE-2022-24254
Description
An unrestricted file upload vulnerability in the Backup/Restore Archive component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted ZIP file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Extensis/Portfoliodescription
Patches
Vulnerability mechanics
References
2- www.whiteoaksecurity.com/blog/extensis-portfolio-vulnerability-disclosure/nvdExploitThird Party Advisory
- snyk.io/research/zip-slip-vulnerabilitynvdTechnical DescriptionThird Party Advisory
News mentions
0No linked articles in our index yet.