EXPOSURES › CVE-2024-24398
CVE-2024-24398
CRITICAL
DETAIL
SourceNVD · cve
Published2024-02-06
CVSS9.8
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-24398 ↗
⚡ RCE
SHAME 50/100
rce
Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the fileName parameter of the Save function.
▸ RECOMMENDED ACTION Remote code execution — patch the affected products on priority.
PLAYERS IMPLICATED
DESCRIPTION
Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the fileName parameter of the Save function.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.