Critical severity9.8NVD Advisory· Published Mar 29, 2024· Updated Apr 15, 2026
CVE-2024-29640
CVE-2024-29640
Description
An issue in aliyundrive-webdav v.2.3.3 and before allows a remote attacker to execute arbitrary code via a crafted payload to the sid parameter in the action_query_qrcode component.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
aliyundrive-webdavcrates.io | <= 2.3.3 | — |
aliyundrive-webdavPyPI | <= 2.3.3 | — |
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- github.com/advisories/GHSA-73v2-rxqp-7q4fghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-29640ghsaADVISORY
- aliyundrive-webdav.comnvdWEB
- github.com/lakemoon602/vuln/blob/main/detail.mdnvdWEB
- github.com/messense/aliyundrive-webdav/blob/main/openwrt/luci-app-aliyundrive-webdav/luasrc/controller/aliyundrive-webdav.luaghsaWEB
News mentions
0No linked articles in our index yet.