Skip to content

Instantly share code, notes, and snippets.

@viniciuspinheiros
Created February 6, 2024 19:52
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save viniciuspinheiros/4e53b297fd6466cf12d01867ee1c9c33 to your computer and use it in GitHub Desktop.
Save viniciuspinheiros/4e53b297fd6466cf12d01867ee1c9c33 to your computer and use it in GitHub Desktop.
[CVE ID]
CVE-2024-24350
[Suggested description]
> File Upload vulnerability in Software Publico e-Sic Livre v.2.0 and
> before allows a remote attacker to execute arbitrary code via the
> extension filtering component.
>
> ------------------------------------------
>
> [VulnerabilityType Other]
> Unrestricted File Upload
>
> ------------------------------------------
>
> [Vendor of Product]
> Software Publico
>
> ------------------------------------------
>
> [Affected Product Code Base]
> e-Sic Livre - <= 2.0
>
> ------------------------------------------
>
> [Affected Component]
> affected source code file.
>
> ------------------------------------------
>
> [Attack Type]
> Remote
>
> ------------------------------------------
>
> [Impact Code execution]
> true
>
> ------------------------------------------
>
> [Attack Vectors]
> To exploit this vulnerability you need to be authenticated.
>
> ------------------------------------------
>
> [Reference]
> https://medium.com/@viniciuspinheiros/e-sic-livre-2-0-authenticated-file-upload-leads-to-remote-code-execution-rce-5937c9537258
>
> ------------------------------------------
>
> [Discoverer]
> Enkrypta Research
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment