VYPR
Unrated severityNVD Advisory· Published Nov 18, 2024· Updated Nov 18, 2024

TRCore DVC - Arbitrary File Upload through Path Traversal

CVE-2024-11311

Description

The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.