CVE-2024-37365
Severity CVSS v4.0:
HIGH
Type:
CWE-20
Input Validation
Publication date:
12/11/2024
Last modified:
12/11/2024
Description
A remote code execution vulnerability exists in the affected<br />
product. The vulnerability allows users to save projects within the public<br />
directory allowing anyone with local access to modify and/or delete files. Additionally,<br />
a malicious user could potentially leverage this vulnerability to escalate<br />
their privileges by changing the macro to execute arbitrary code.
Impact
Base Score 4.0
7.00
Severity 4.0
HIGH
Base Score 3.x
7.30
Severity 3.x
HIGH



