Critical severity9.8NVD Advisory· Published Apr 16, 2025· Updated Jun 17, 2026
CVE-2024-55371
CVE-2024-55371
Description
Wallos <= 2.38.2 has a file upload vulnerability in the restore backup function, which allows authenticated users to restore backups by uploading a ZIP file. The contents of the ZIP file are extracted on the server. This functionality enables an authenticated attacker (being an administrator is not required) to upload malicious files to the server. Once a web shell is installed, the attacker gains the ability to execute arbitrary commands.
Affected products
3- Wallos/Wallosdescription
Patches
Vulnerability mechanics
References
1- www.datafarm.co.th/blog/CVE-2024-55371-and-CVE-2024-55372-Malicious-File-Upload-to-RCE-in-Wallos-ApplicationnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.