CVE-2024-11315

Severity CVSS v4.0:
Pending analysis
Type:
CWE-23 Relative Path Traversal
Publication date:
18/11/2024
Last modified:
20/11/2024

Description

The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:trcore:dvc:*:*:*:*:*:*:*:* 6.0 (including) 6.4 (excluding)